Vulnerabilities > Direct Request ('Forced Browsing')

DATE CVE VULNERABILITY TITLE RISK
2022-06-14 CVE-2021-40616 Forced Browsing vulnerability in Thinkcmf 5.1.7
thinkcmf v5.1.7 has an unauthorized vulnerability.
network
low complexity
thinkcmf CWE-425
6.5
2022-06-10 CVE-2021-44582 Forced Browsing vulnerability in Money Transfer Management System Project Money Transfer Management System 1.0
A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.
6.5
2022-06-06 CVE-2022-31480 Forced Browsing vulnerability in multiple products
An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS).
network
low complexity
hidglobal carrier CWE-425
5.0
2022-06-06 CVE-2022-31484 Forced Browsing vulnerability in multiple products
An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface.
network
low complexity
hidglobal carrier CWE-425
5.0
2022-06-06 CVE-2022-31485 Forced Browsing vulnerability in multiple products
An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the web interface.
network
low complexity
hidglobal carrier CWE-425
5.0
2022-06-02 CVE-2022-28799 Forced Browsing vulnerability in Tiktok
The TikTok application before 23.7.3 for Android allows account takeover.
network
low complexity
tiktok CWE-425
8.8
2022-05-20 CVE-2022-28991 Forced Browsing vulnerability in Bdtask Multi Store Inventory Management System 1.0
Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.
network
low complexity
bdtask CWE-425
7.5
2022-04-27 CVE-2021-34588 Forced Browsing vulnerability in Bender Cc612 Firmware and Icc15Xx Firmware
In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export.
network
low complexity
bender CWE-425
5.0
2022-04-16 CVE-2022-26653 Forced Browsing vulnerability in Zohocorp Manageengine Remote Access Plus
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
network
low complexity
zohocorp CWE-425
5.3
2022-04-16 CVE-2022-26777 Forced Browsing vulnerability in Zohocorp Manageengine Remote Access Plus
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
network
low complexity
zohocorp CWE-425
5.3