CWE-425: Forced Browsing

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

100 tracked CVEs are classified under this weakness.

Highest-risk vulnerabilities

Recently published

Browse the full CVE database