CWE-425Base1 in KEV

Direct Request ('Forced Browsing')

Incomplete in the CWE catalog · 102 CVEs mapped

102
CVEs mapped
1
In KEV
5.8
Median CVSS
What it is

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Recent examples
5.3cvss
CVE-2026-78051

CVE-2026-78051 - MEDIUM Severity Vulnerability

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2026.06.20 is sufficient to resolve this issue. Patch name: ce897ee00903bf7ded406f0d7852d95dd4164add. You should upgrade the affected component.

MEDIUMno explanation yet
0%
epss
4.3cvss
CVE-2026-14953

CVE-2026-14953 - MEDIUM Severity Vulnerability

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2026-76799

CVE-2026-76799 - MEDIUM Severity Vulnerability

A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation causes files or directories accessible. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-425
Abstraction
Base
Structure
Simple
Status
Incomplete