The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-40248
HIGH
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions
CVSS 7.5
CVE-2026-40247
HIGH
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions
CVSS 7.5
CVE-2026-40246
HIGH
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
CVSS 7.5
CVE-2026-34370
MEDIUM
Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes
CVSS 6.5
CVE-2026-33146
MEDIUM
Docmost's Public Share Search Exposes Metadata of Restricted Children
CVSS 4.3
CVE-2026-27912
HIGH
Windows Kerberos Elevation of Privilege Vulnerability
CVSS 8.0
CVE-2026-38533
MEDIUM
Snipe-IT 8.4.0 - Privilege Escalation
CVSS 6.5
CVE-2026-6105
HIGH
perfree go-fastdfs-web doInstall InstallController.java improper authorization
CVSS 7.3
CVE-2026-32252
HIGH
Chartbrew Cross-Tenant Template Export and Secret Disclosure in `GET /team/:team_id/template/generate/:project_id`
CVSS 7.7
CVE-2026-5412
CRITICAL
Juju CloudSpec API could leak senstive information
CVSS 9.9
CVE-2026-5999
MEDIUM
JeecgBoot SysAnnouncementController improper authorization
CVSS 6.3
CVE-2026-5842
HIGH
decolua 9router Administrative API Endpoint api authorization
CVSS 7.3
CVE-2026-39901
MEDIUM
monetr: Protected Transactions Deletable via PUT
CVSS 5.7
CVE-2026-35479
MEDIUM
InvenTree Plugin Installation - Insufficient Permissions
CVSS 6.6
CVE-2026-35476
HIGH
InvenTree Affected by Privilege Escalation via API
CVSS 7.2
CVE-2026-35407
MEDIUM
Saleor has Cross-Account Email Change via Unbound Confirmation Token
CVSS 6.5
CVE-2026-39389
MEDIUM
CI4MS <0.31.4.0 Fileeditor Hidden Items - Authorization Bypass
CVSS 6.7
CVE-2026-39347
LOW
OrangeHRM's Self‑Appraisal Submission of Admin Users Can Be Modified After Completion
CVSS 2.7
CVE-2026-35610
HIGH
PolarLearn <=0-PRERELEASE-14 Account Management - Admin Bypass
CVSS 8.8
CVE-2026-5642
HIGH
Cyber-III Student-Management-System HTTP POST Request update.php improper authorization
CVSS 7.3
CVE-2026-5529
MEDIUM
Dromara lamp-cloud DefUserController pageUser improper authorization
CVSS 4.3
CVE-2026-33105
CRITICAL
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-32213
CRITICAL
Azure AI Foundry Elevation of Privilege Vulnerability
CVSS 10.0
CVE-2026-33950
CRITICAL
signalk-server: Privilege Escalation by Admin Role Injection via /enableSecurity
CVSS 9.4
CVE-2026-5326
MEDIUM
SourceCodester Leave Application System User Information index.php authorization
CVSS 5.3
Details
Vulnerabilities
1,461
Exploit Likelihood
High