The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-60911
MEDIUM
Oracle Property Manager 12.2.3-12.2.15 - Authenticated Data Modification and Information Disclosure via HTTP
CVSS 5.4
CVE-2026-60886
HIGH
Oracle Work in Process 12.2.3-12.2.15 - Authenticated Data Access and Modification via HTTP with User Interaction
CVSS 7.6
CVE-2026-60844
HIGH
Oracle Customer Support 12.2.3-12.2.15 Auth Bypass via Update Service Request Leads to Data Modification/Access
CVSS 8.1
CVE-2026-60842
MEDIUM
Oracle Knowledge Mgmt 12.2.5-12.2.15: Unauth CSRF & Data Disclosure via HTTP Search
CVSS 6.1
CVE-2026-60152
MEDIUM
PeopleSoft Enterprise PeopleTools 8.61 and 8.62 - Unauthenticated Cross-Site Request Forgery via Panel Processor
CVSS 5.4
CVE-2026-47053
MEDIUM
Oracle VM VirtualBox - Denial of Service
CVSS 5.6
CVE-2026-28312
CRITICAL
SolarWinds Serv-U Privilege Escalation Vulnerability
CVSS 9.1
CVE-2026-16450
MEDIUM
zsadmin2025 ZS-Admin MyBatis-Plus Tenant Plugin page getTenantId authorization
CVSS 4.3
CVE-2026-34239
HIGH
Chamilo Authenticated Remote Code Execution
CVE-2026-32821
HIGH
API Collection Impersonation Via user_email And Missing Object- Level Authorization
CVSS 8.1
CVE-2026-32819
MEDIUM
dataCycle User Directory Enumeration Via /users/search
CVSS 4.3
CVE-2026-32806
HIGH
dataCycle Authorization Bypass Via /remote_render
CVSS 7.5
CVE-2026-32807
HIGH
dataCycle Public DataLink Text File Download Ignores Validity And Authorization
CVSS 7.5
CVE-2026-27823
HIGH
EGroupware <= 23.1.20260131/26.2.20260216 - Remote Code Execution
CVE-2026-63752
MEDIUM
SurrealDB before 3.1.0 RELATE Statement Record Overwrite
CVSS 4.3
CVE-2026-16224
MEDIUM
jxxghp MoviePilot Application API improper authorization
CVSS 4.3
CVE-2026-16217
MEDIUM
guohongze adminset Delivery Deployment Endpoint deli.py authorization
CVSS 6.3
CVE-2026-16214
MEDIUM
geex-arts django-jet Dashboard views.py authorization
CVSS 6.3
CVE-2026-16200
HIGH
zevorn rt-claw RPC swarm.c claw_tool_invoke authorization
CVSS 7.3
CVE-2026-16199
MEDIUM
nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper authorization
CVSS 6.3
CVE-2026-16195
MEDIUM
Sipeed PicoClaw Group Message wecom.go dispatchIncoming authorization
CVSS 6.3
CVE-2026-16126
HIGH
zevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorization
CVSS 7.3
CVE-2026-16122
MEDIUM
nextlevelbuilder GoClaw exec_approval.go matchesAllowlist authorization
CVSS 4.3
CVE-2026-16121
MEDIUM
nextlevelbuilder GoClaw exec_approval.go isSafeBin improper authorization
CVSS 6.3
CVE-2026-16119
MEDIUM
nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization
CVSS 6.3
Details
Vulnerabilities
1,461
Exploit Likelihood
High