The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-14778
HIGH
SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
CVSS 7.3
CVE-2026-14753
HIGH
mjperpinosa stumasy Note Handler/Assignment notes authorization
CVSS 7.3
CVE-2026-14716
MEDIUM
nextlevelbuilder GoClaw WebSocket RPC router.go MethodRouter.Handle authorization
CVSS 6.3
CVE-2026-14693
MEDIUM
SourceCodester Multi-Vendor Online Grocery Management System Master.php cancel_order improper authorization
CVSS 5.4
CVE-2026-14690
HIGH
SourceCodester Multi-Vendor Online Grocery Management System Users.php save_users improper authorization
CVSS 7.3
CVE-2026-58424
HIGH
Gitea Open Source Git Server - Permanent Fork PR Workflow Approval Gate Bypass
CVSS 8.9
CVE-2026-58284
HIGH
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVSS 8.3
CVE-2026-57983
HIGH
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVSS 8.7
CVE-2026-14608
MEDIUM
SourceCodester CET Automated Grading System with AI Predictive Analytics POST index.php view_student authorization
CVSS 4.3
CVE-2026-50279
HIGH
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
CVE-2026-56350
MEDIUM
n8n - SSO Enforcement Bypass via API
CVSS 6.3
CVE-2026-56320
HIGH
Capgo - Org/App Scope Mismatch in Device Creation Endpoint
CVSS 7.1
CVE-2026-56249
HIGH
Capgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /channel Name Collision
CVSS 7.6
CVE-2026-7663
CRITICAL
IBM Langflow OSS 1.0.0-1.9.6 - Unauthenticated MCP Authorization Bypass
CVSS 9.1
CVE-2026-6556
CRITICAL
@fastify/express vulnerable to middleware bypass via non-string mount paths in prefixed plugins
CVSS 9.1
CVE-2026-49877
HIGH
Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console
CVSS 8.1
CVE-2026-55956
MEDIUM
Apache Tomcat: Security constraints for default servlet ignored method
CVSS 6.5
CVE-2026-13591
MEDIUM
DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization
CVSS 5.0
CVE-2026-13549
MEDIUM
CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization
CVSS 5.4
CVE-2026-13534
MEDIUM
CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
CVSS 5.0
CVE-2026-13524
MEDIUM
CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization
CVSS 5.6
CVE-2026-13514
LOW
Chess Play and Learn App com.chess AndroidManifest.xml backup
CVSS 2.4
CVE-2026-13512
MEDIUM
Databend Tenant client_session_manager.rs state_key authorization
CVSS 6.3
CVE-2026-13511
LOW
VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authorization
CVSS 3.1
CVE-2026-13508
MEDIUM
khoj-ai khoj Conversation Sharing api_chat.py authorization
CVSS 5.5
Details
Vulnerabilities
1,461
Exploit Likelihood
High