Vulnerabilities > Direct Request ('Forced Browsing')

DATE CVE VULNERABILITY TITLE RISK
2019-10-11 CVE-2019-17503 Forced Browsing vulnerability in Kirona Dynamic Resource Scheduling 5.5.3.5
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5.
network
low complexity
kirona CWE-425
5.3
2019-09-20 CVE-2019-11326 Forced Browsing vulnerability in Topcon Net-G5 Firmware 5.2.2
An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2.
network
low complexity
topcon CWE-425
8.8
2019-09-11 CVE-2019-1220 Forced Browsing vulnerability in Microsoft Edge and Internet Explorer
A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'.
network
low complexity
microsoft CWE-425
4.3
2019-08-14 CVE-2019-9584 Forced Browsing vulnerability in Eq-3 Homematic Ccu2 Firmware and Homematic Ccu3 Firmware
eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain VPN profile details, shutting down the VPN service and to delete the VPN service configuration.
network
low complexity
eq-3 CWE-425
critical
9.8
2019-08-14 CVE-2019-13030 Forced Browsing vulnerability in Mediola NEO Server
eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to start or stop the Node.js process, resulting in the ability to obtain mediola configuration details.
network
low complexity
mediola CWE-425
8.2
2019-08-06 CVE-2019-14347 Forced Browsing vulnerability in Schben Adive
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.
network
low complexity
schben CWE-425
8.8
2019-07-25 CVE-2019-9884 Forced Browsing vulnerability in Eclass IP 2.5
eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.
network
low complexity
eclass CWE-425
critical
9.8
2019-07-19 CVE-2019-13981 Forced Browsing vulnerability in Rangerstudio Directus 7 API
In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory.
network
low complexity
rangerstudio CWE-425
5.3
2019-06-27 CVE-2019-12583 Forced Browsing vulnerability in Zyxel products
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator.
network
low complexity
zyxel CWE-425
critical
9.1
2019-06-20 CVE-2019-1899 Forced Browsing vulnerability in Cisco Rv110W Firmware, Rv130W Firmware and Rv215W Firmware
A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network.
network
low complexity
cisco CWE-425
5.3