Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-425

MITRE ↗

CWE-425

2
CRITICAL
8
HIGH
17
MEDIUM
2
LOW
32 CVEs
9.4
CVE-2025-52024

A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin

9.1
CVE-2026-22732

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility

8.8
CVE-2026-35029

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/updat

8.3
CVE-2026-42297

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve

7.7
CVE-2026-34056

OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access

7.5
CVE-2026-0790

ALGO 8180 IP Audio Alerter Web UI Direct Request Information Disclosure Vulnerability. This vulnerability allows remote

7.5
CVE-2026-25679

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

7.2
CVE-2026-10521

An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user,

7.1
CVE-2026-33217

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1

7.1
CVE-2025-15381

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not p

5.4
CVE-2026-32867

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number

5.4
CVE-2026-34051

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior

5.4
CVE-2026-7500

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled

5.3
CVE-2026-1978

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the

5.3
CVE-2026-4532

A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vuln

5.3
CVE-2026-4900

A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil

5.3
CVE-2026-29909

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/f

5.3
CVE-2026-8205

Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does no

5.3
CVE-2026-13533

A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function

5.3
CVE-2026-60011

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image

5.3
CVE-2026-19903

A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db

5.3
CVE-2026-76799

A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the f

5.3
CVE-2026-78051

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the f

4.9
CVE-2026-11986

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabi

4.6
CVE-2026-21760

HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a

4.3
CVE-2024-58343

Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie d

4.3
CVE-2026-14953

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges

3.7
CVE-2024-23573

HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13

2.3
CVE-2026-9610

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality

CVE-2026-0650

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware.

CVE-2025-15587

Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an admini

CVE-2026-34028

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not pr

Frequently Asked Questions

What is CWE-425?

CWE-425 (CWE-425) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-425?

There are 32 CVE records associated with CWE-425 in our database. Of these, 2 are critical severity, 8 are high severity, and 17 are medium severity.

How can I protect against CWE-425 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-425 using AI-powered security agents.

Detect CWE-425 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-425 vulnerabilities across your infrastructure.

Get Started