Threats Tagged 'cwe-425'
View all threats tagged with 'cwe-425'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-425'
Click on any threat for detailed analysis and mitigation recommendations
Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints. Join the discussion | CVE Database V5 | 10/02/2026, 21:51:34 UTC Added: 10/02/2026, 22:01:54 UTC |
0 Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password. Join the discussion | CVE Database V5 | 10/01/2026, 05:51:37 UTC Added: 10/01/2026, 14:56:28 UTC |
0 A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control. Join the discussion | CVE Database V5 | 08/25/2026, 11:41:32 UTC Added: 06/11/2026, 18:00:08 UTC |
0 CVE-2026-14953 is a medium severity vulnerability in Frauscher Sensortechnik FDS 102 versions 2.11.0 through 2.13.3. It allows a low-privileged remote attacker to enumerate all configured users and determine which accounts have elevated privileges via the /api/user/fetch-all.php endpoint. This is a direct request (forced browsing) vulnerability categorized under CWE-425. Join the discussion | CVE Database V5 | 08/20/2026, 08:20:06 UTC Added: 08/20/2026, 08:37:45 UTC |
0 A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Join the discussion | CVE Database V5 | 08/15/2026, 17:45:07 UTC Added: 08/15/2026, 17:56:46 UTC |
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted administrative functionality by directly accessing protected application endpoints. Join the discussion | CVE Database V5 | 07/17/2026, 17:06:19 UTC Added: 07/18/2026, 11:08:38 UTC |
0 HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack. Join the discussion | CVE Database V5 | 07/17/2026, 13:42:13 UTC Added: 07/18/2026, 11:08:58 UTC |
Release of RHOAI 3.3.4 provides these changes: Join the discussion | GCVE Database | 06/25/2026, 18:09:56 UTC Added: 06/24/2026, 16:59:22 UTC |
0 An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability. Join the discussion | CVE Database V5 | 06/23/2026, 07:34:10 UTC Added: 06/23/2026, 08:09:14 UTC |
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls. Join the discussion | CVE Database V5 | 06/22/2026, 14:22:34 UTC Added: 06/22/2026, 15:39:23 UTC |
Showing 1 to 10 of 28 results