CWE-425
CVEs classified under CWE-425, newest first.
9 CVEsRSS
CVE-2026-40532Medium· 6.5A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.
A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.
CVE-2026-36453High· 7.4Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1
Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
CVE-2026-19903Medium· 5.3A vulnerability has been found in SourceCodester Online Clothing Store 1.0
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote…
CVE-2026-13533Medium· 5.3A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or…
CVE-2026-11986Medium· 4.9A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when …
CVE-2026-7500Medium· 5.4When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write…
CVE-2026-33217High· 7.1NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing M…
CVE-2026-25679High· 7.5url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-0650NonePoCOpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware
OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and…