The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2025-64523
HIGH
filebrowser < 2.45.1 - Authenticated Insecure Direct Object Reference in Share Deletion
CVSS 8.8
CVE-2025-11521
HIGH
Astra Security Suite - Firewall & Malware Scan <0.3 - RCE
CVSS 8.1
CVE-2025-12435
MEDIUM
Google Chrome < 142.0.7444.59 - Security UI Spoofing via Omnibox
CVSS 5.4
CVE-2025-63691
CRITICAL
pig4cloud/pig < 3.8.2 - Authenticated Information Disclosure via Token Management Interface
CVSS 9.6
CVE-2025-12854
LOW
newbee-mall-plus <2.4.1 - Auth Bypass
CVSS 3.7
CVE-2025-4519
HIGH
IDonate 2.1.5-2.1.9 Authenticated Privilege Escalation via Missing Capability Check
CVSS 8.8
CVE-2025-12360
MEDIUM
Better Find and Replace - AI-Powered Suggestions <1.7.7 - Open Redi...
CVSS 4.3
CVE-2025-60784
MEDIUM
XiaozhangBang Voluntary Like System V8.8 - Info Disclosure
CVSS 6.5
CVE-2025-62520
MEDIUM
MantisBT < 2.27.2 - Improper Authorization via Copy From Action
CVSS 4.3
CVE-2025-12623
LOW
fushengqian fuint <41e26be8a2c609413a0feaa69bdad33a71ae8032 - Auth ...
CVSS 3.1
CVE-2025-12367
MEDIUM
SiteSEO - SEO Simplified <1.3.1 - Auth Bypass
CVSS 4.3
CVE-2025-11174
MEDIUM
Document Library Lite <1.1.6 - Auth Bypass
CVSS 5.3
CVE-2025-12304
MEDIUM
TIME-SEA-PLUS <fb299162f18498dd9cf17da906886d80a077d53b - Auth Bypass
CVSS 4.3
CVE-2025-12288
MEDIUM
Bdtask Pharmacy Management System < 9.4 - Improper Authorization in User Profile Handler
CVSS 4.3
CVE-2025-12283
MEDIUM
code-projects Client Details System 1.0 - Improper Authorization
CVSS 4.3
CVE-2025-6639
MEDIUM
Tutor LMS Pro - Insecure Direct Object Reference
CVSS 5.4
CVE-2025-12005
MEDIUM
WP VR - 360 Panorama & Free Virtual Tour Builder For WordPress <8.5...
CVSS 4.3
CVE-2025-11879
MEDIUM
GenerateBlocks <2.1.1 - Info Disclosure
CVSS 6.5
CVE-2025-11244
LOW
Password Protected <2.7.11 - Auth Bypass
CVSS 3.7
CVE-2025-10902
MEDIUM
Originality.ai AI Checker <1.0.12 - Info Disclosure
CVSS 4.3
CVE-2025-62401
MEDIUM
Moodle 4.1.0-4.1.20 and 5.0.0-beta-5.0.2 - Improper Authorization in Timed Assignment Feature
CVSS 5.4
CVE-2025-62610
HIGH
Hono 1.1.0-4.10.1 - Improper Authorization via JWT Audience Claim Mismatch
CVSS 8.1
CVE-2025-22177
MEDIUM
Jira Align 11.14.0-11.16.0 - Improper Authorization
CVSS 4.3
CVE-2025-22176
MEDIUM
Jira Align 11.14.0-11.16.0 - Improper Authorization
CVSS 4.3
CVE-2025-22175
MEDIUM
Jira Align 11.14.0-11.16.0 - Improper Authorization via Private Checklist Endpoint
CVSS 5.4
Details
Vulnerabilities
1,461
Exploit Likelihood
High