CWE-425: CWE-425
Yearly Trend
Top Affected Vendors
All CWE-425 CVEs (42)
This vulnerability allows remote attackers to perform unauthenticated file operations on ClearML's fileserver component. Attackers can read, create, m...
Feb 6, 2024This vulnerability allows an unauthenticated attacker to bypass authentication in Fortra's GoAnywhere MFT and create an administrative user via the ad...
Jan 22, 2024EyouCMS v1.5.5 lacks access control on the /data/sqldata component, allowing unauthenticated attackers to directly access sensitive database files. Th...
Mar 24, 2022CVE-2021-36560 is an authentication bypass vulnerability in Phone Shop Sales Management System 1.0 that allows attackers to gain admin access without ...
Nov 2, 2021This vulnerability allows remote attackers to bypass authentication mechanisms in Trend Micro ServerProtect products, potentially gaining unauthorized...
Sep 29, 2021This vulnerability allows attackers to bypass authentication on D-Link DAP-1650 wireless range extenders by accessing restricted web interface pages w...
Dec 30, 2020This vulnerability allows unauthenticated remote attackers to download the router configuration file containing sensitive information like admin passw...
Jan 1, 2021This vulnerability allows remote attackers to escalate privileges to Admin role in Sourcecodester Money Transfer Management System 1.0 by accessing an...
Jun 10, 2022This vulnerability in TikTok for Android allows attackers to take over user accounts through a malicious deeplink. Attackers can craft a URL that forc...
Jun 2, 2022The reint_downloadmanager extension for TYPO3 contains an Insecure Direct Object Reference vulnerability that allows attackers to access unauthorized ...
May 21, 2025The sr_feuser_register extension for TYPO3 contains an Insecure Direct Object Reference vulnerability that allows attackers to access or modify user r...
May 21, 2025The Oz Forensics face recognition application before version 4.0.8 (late 2023) contains an Insecure Direct Object Reference (IDOR) vulnerability in th...
Apr 11, 2025This vulnerability in Bender/ebee Charge Controllers allows attackers to access unprotected data exports after device reboot. The backup export featur...
Apr 27, 2022An authentication bypass vulnerability in SINEMA Remote Connect Server allows unauthenticated attackers to access and modify VxLAN network configurati...
Jul 9, 2024This vulnerability allows remote attackers to access sensitive information on ALGO 8180 IP Audio Alerter devices without authentication by directly na...
Jan 23, 2026This CVE describes a Direct Request (Forced Browsing) vulnerability in Apache OFBiz that allows attackers to access restricted resources by directly r...
Sep 4, 2024This vulnerability allows authenticated users without administrative privileges to access admin functions in IBM Cloud Pak for Multicloud Management M...
Feb 8, 2023This vulnerability in WAVLINK WN579 X3 routers allows attackers to access sensitive key information by visiting the messages.txt page without authenti...
Jul 25, 2022This vulnerability allows unauthenticated attackers to remotely download configuration files from D-Link DIR850 routers. Attackers can access sensitiv...
Mar 4, 2022CVE-2021-42671 is an incorrect access control vulnerability in Sourcecodester Engineers Online Portal that allows unauthenticated attackers to access ...
Nov 5, 2021CVE-2021-40875 is an improper access control vulnerability in Gurock TestRail that allows unauthenticated attackers to access the /files.md5 file, rev...
Sep 22, 2021This vulnerability allows unauthenticated attackers to access sensitive database backup files in TCExam installations. It affects all TCExam installat...
Jul 30, 2021In flaskBlog versions 2.8.0 and earlier, any authenticated user can escalate their privileges to admin by exploiting a vulnerability in the admin pane...
Aug 19, 2025Innoshop versions through 0.4.1 contain multiple Insecure Direct Object Reference (IDOR) vulnerabilities in the frontend shop. Attackers with customer...
Jun 23, 2025A direct request vulnerability in kalyan02 NanoCMS up to version 0.4 allows attackers to remotely manipulate the /data/pagesdata.txt file through the ...
Feb 6, 2026Frappe Learning versions 2.39.1 and earlier contain a direct object reference vulnerability where students can access quiz forms by knowing the URL, b...
Oct 27, 2025The femanager extension for TYPO3 contains an Insecure Direct Object Reference vulnerability that allows authenticated users to access or modify data ...
May 21, 2025This vulnerability in SourceCodester Clinics Patient Management System 1.0 allows attackers to directly access files in the /user_images/ directory wi...
Aug 14, 2024This vulnerability in Netgear WN604 access points allows attackers to directly access the siteSurvey.php file without proper authentication. This coul...
Jul 27, 2024This vulnerability in Parsec Automation TrakSYS allows attackers to directly access export pages by manipulating the ID parameter, potentially exposin...
Jun 30, 2024This vulnerability in Parsec Automation TrackSYS allows attackers to directly access sensitive files by manipulating the ID parameter in the /TS/expor...
Jun 20, 2024This vulnerability in Mintlify Platform's GitHub Integration API allows attackers to access sensitive repository metadata by exploiting improper valid...
Dec 19, 2025CVE-2025-47226 is an authorization bypass vulnerability in Snipe-IT that allows unauthorized access to asset information. Attackers can exploit incorr...
May 2, 2025Ververica Platform 2.14.0 contains an improper authorization vulnerability that allows low-privileged users to access SQL connectors they shouldn't ha...
Apr 27, 2025This vulnerability allows authenticated GitLab users to view sensitive security report information under specific configuration conditions. It affects...
Nov 26, 2025This CVE describes a forced browsing vulnerability in iroha Board that allows authenticated attackers to access non-public content by directly request...
Jun 26, 2025This vulnerability in Grocy allows remote attackers to access sensitive information by directly requesting pages not visible in the user interface, su...
Jan 6, 2025This vulnerability in PbootCMS allows attackers to access sensitive files or directories through manipulation of the SQLite database file. It affects ...
Dec 28, 2025This vulnerability in Shenzhen Sixun Software Sixun Shanghui Group Business Management System allows unauthorized access to files or directories via t...
Dec 15, 2025A forced browsing vulnerability in Fortinet FortiAuthenticator allows authenticated attackers with sponsor permissions to access and download device l...
Dec 9, 2025This vulnerability allows unauthorized users to access router configuration files by directly referencing them via URL. It affects WODESYS WD-R608U ro...
Dec 18, 2025This vulnerability (CWE-425: Direct Request) allows attackers to bypass intended access controls and retrieve sensitive information by directly access...
Dec 17, 2025About CWE-425 (CWE-425)
Our database tracks 42 CVEs classified as CWE-425, with 7 rated critical and 15 rated high severity. The average CVSS score for CWE-425 vulnerabilities is 6.9.
External reference: View CWE-425 on MITRE CWE →
Monitor CWE-425 Vulnerabilities
Get alerted when new CWE-425 CVEs affect your infrastructure.
Start Monitoring Free