The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-7144
MEDIUM
1000 Projects Portfolio Management System MCA update_passwd_process.php authorization
CVSS 4.3
CVE-2026-7142
MEDIUM
Wooey API Endpoint scripts.py add_or_update_script improper authorization
CVSS 6.3
CVE-2026-7109
MEDIUM
code-projects Invoice System in Laravel API Endpoint item improper authorization
CVSS 5.3
CVE-2026-7093
MEDIUM
code-projects Invoice System in Laravel Invoice Endpoint invoice improper authorization
CVSS 6.3
CVE-2026-7092
MEDIUM
code-projects Invoice System in Laravel Profile profile improper authorization
CVSS 6.3
CVE-2026-7091
MEDIUM
code-projects Invoice System in Laravel User Management user improper authorization
CVSS 6.3
CVE-2026-6977
HIGH
vanna-ai vanna Legacy Flask API improper authorization
CVSS 7.3
CVE-2026-34321
MEDIUM
Oracle Financial Services Analytical Applications Infrastructure - Unauthorized Data Access
CVSS 4.8
CVE-2026-34320
HIGH
Oracle Financial Services Customer Screening 8.1.2.8.0 - Info Disclosure
CVSS 7.5
CVE-2026-34315
MEDIUM
Oracle WebLogic Server 12.2.1.4.0 to 15.1.1.0.0 - Unauthorized Data Modification
CVSS 6.5
CVE-2026-6634
MEDIUM
usememos UpdateInstanceSetting App.tsx memos_access_token improper authorization
CVSS 6.3
CVE-2026-6614
MEDIUM
TransformerOptimus SuperAGI project.py get_projects_organisation authorization
CVSS 6.3
CVE-2026-6613
MEDIUM
TransformerOptimus SuperAGI agent.py get_schedule_data authorization
CVSS 6.3
CVE-2026-6612
MEDIUM
TransformerOptimus SuperAGI Agent Execution Endpoint agent_execution.py update_agent_execution authorization
CVSS 6.3
CVE-2026-6609
MEDIUM
liangliangyy DjangoBlog views.py form_valid improper authorization
CVSS 6.3
CVE-2026-6586
MEDIUM
TransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorization
CVSS 6.3
CVE-2026-6585
MEDIUM
TransformerOptimus SuperAGI Organisation Update Endpoint organisation.py update_organisation authorization
CVSS 5.4
CVE-2026-6584
MEDIUM
TransformerOptimus SuperAGI User Update Endpoint user.py update_user authorization
CVSS 5.4
CVE-2026-6583
MEDIUM
TransformerOptimus SuperAGI API Key Management Endpoint api_key.py edit_api_key authorization
CVSS 5.4
CVE-2026-6572
MEDIUM
Collabora KodExplorer fileUpload Endpoint share.class.php improper authorization
CVSS 5.6
CVE-2026-6571
MEDIUM
kodcloud KodExplorer systemRole.class.php roleGroupAction authorization
CVSS 6.3
CVE-2026-6570
LOW
kodcloud KodExplorer systemMember.class.php initInstall authorization
CVSS 2.7
CVE-2026-6564
MEDIUM
EMQ EMQX Enterprise Session Handling improper authorization
CVSS 4.3
CVE-2026-40305
MEDIUM
DNN has Force Friend Request Acceptance
CVSS 4.3
CVE-2026-40259
HIGH
SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView API
CVSS 8.1
Details
Vulnerabilities
1,461
Exploit Likelihood
High