The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-2015
MEDIUM
Portabilis i-Educar <2.10 - Privilege Escalation
CVSS 6.3
CVE-2026-2010
MEDIUM
Sanluan PublicCMS <4.0-6.202506.d - Privilege Escalation
CVSS 4.2
CVE-2026-23623
MEDIUM
Collabora Online <25.04.08.2, <23.05.20.1, <24.04.17.3, <25.04.7.5 ...
CVSS 5.3
CVE-2026-1894
MEDIUM
Wekan < 8.21 - Improper Authorization via REST API Checklist Items Manipulation
CVSS 6.3
CVE-2026-1892
MEDIUM
Wekan < 8.21 - Improper Authorization via setBoardOrgs Function
CVSS 5.0
CVE-2026-1733
MEDIUM
crmeb < 5.6.3 - Improper Authorization via Order ID Manipulation
CVSS 4.3
CVE-2026-1702
MEDIUM
Pet Grooming Management Software 1.0 - Incorrect Privilege Assignment in User Management
CVSS 6.3
CVE-2026-1597
MEDIUM
Bdtask SalesERP <20260116 - Auth Bypass
CVSS 6.3
CVE-2026-1550
MEDIUM
PHPGurukul Hospital Management System 1.0 - Incorrect Privilege Assignment in Admin Dashboard Page
CVSS 6.3
CVE-2026-24835
HIGH
Podman Desktop <1.25.1 - Auth Bypass
CVSS 7.1
CVE-2026-24305
CRITICAL
Azure Entra ID < - Privilege Escalation
CVSS 9.3
CVE-2026-22022
HIGH
Apache Solr 5.3.0-9.10.0 - Improper Authorization in RuleBasedAuthorizationPlugin
CVSS 8.2
CVE-2026-21641
MEDIUM
Revive Adserver < 6.0.4 - Improper Authorization in Tracker Deletion
CVSS 6.5
CVE-2026-1193
MEDIUM
MineAdmin 1.x/2.x - Improper Authorization in View Interface
CVSS 6.3
CVE-2026-1141
MEDIUM
PHPGurukul News Portal 1.0 - Incorrect Privilege Assignment in Add Sub-Admin Page
CVSS 6.3
CVE-2026-1112
MEDIUM
PublicCMS < 5.202506.d - Improper Authorization via Trade Address Deletion Endpoint
CVSS 5.4
CVE-2026-1106
MEDIUM
Chamilo LMS <2.0.0 Beta 1 - Auth Bypass
CVSS 5.4
CVE-2026-20960
HIGH
Microsoft Power Apps - Code Injection
CVSS 8.0
CVE-2026-22252
CRITICAL
LibreChat < 0.8.2-rc2 - Authenticated Remote Code Execution via MCP Stdio Transport
CVSS 9.1
CVE-2026-22042
HIGH
RustFS < 1.0.0-alpha.79 - Unauthorized IAM Import via Incorrect Action Validation
CVSS 8.8
CVE-2026-0574
MEDIUM
yeqifu warehouse <aaf29962ba407d22d991781de28796ee7b4670e4 - Privil...
CVSS 6.3
CVE-2025-68712
MEDIUM
SpSoft AppLock 7.9.40 - Authentication Bypass via Insecure Interface Navigation
CVSS 5.5
CVE-2025-43289
MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure via Logic Issue
CVSS 5.5
CVE-2025-9988
MEDIUM
Broadstreet <= 1.53.1 - Missing Authorization to Authenticated (Subscriber+) Advertiser Creation
CVSS 4.3
CVE-2025-67259
MEDIUM
ClassroomIO 0.1.13 - Broken Access Control
CVSS 6.5
Details
Vulnerabilities
1,461
Exploit Likelihood
High