The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
1,461 vulnerabilities with CWE-285
CVE-2026-46668
LOW
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
CVE-2026-47298
HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS 8.0
CVE-2026-45503
HIGH
Microsoft Exchange Server Information Disclosure Vulnerability
CVSS 8.1
CVE-2026-45490
HIGH
Microsoft .NET - Local Privilege Escalation
CVSS 7.8
CVE-2026-42902
HIGH
Microsoft PowerToys Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-11619
MEDIUM
Dolibarr ERP CRM Legacy Filemanager config.inc.php improper authorization
CVSS 6.3
CVE-2026-46484
HIGH
Headplane renameNode - Authenticated Path Traversal and RBAC Bypass
CVSS 8.1
CVE-2026-11533
MEDIUM
imvks786 student_management_system Student Deletion Endpoint see.php improper authorization
CVSS 5.4
CVE-2026-46656
HIGH
Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions
CVSS 8.8
CVE-2026-11521
MEDIUM
Mohammed-eid35 bank-management-system-springboot Transaction Endpoint TransactionController.java improper authorization
CVSS 6.3
CVE-2026-11519
MEDIUM
SourceCodester Inventory System Account Creation users_handler.php improper authorization
CVSS 6.3
CVE-2026-11500
MEDIUM
Weaviate Static API Key client.go validateConfig authorization
CVSS 5.0
CVE-2026-11476
MEDIUM
Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization
CVSS 6.3
CVE-2026-11462
HIGH
Chengdu Everbrite Network Technology BeikeShop Stripe Plugin StripeController.php callback improper authorization
CVSS 7.3
CVE-2026-11461
MEDIUM
NousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization
CVSS 6.3
CVE-2026-11441
MEDIUM
theonedev Pull Request issues canAccessIssue improper authorization
CVSS 6.3
CVE-2026-11440
MEDIUM
theonedev REST API default-branch improper authorization
CVSS 6.3
CVE-2026-11439
MEDIUM
theonedev Parent Project projects improper authorization
CVSS 6.3
CVE-2026-11438
MEDIUM
theonedev projects improper authorization
CVSS 6.3
CVE-2026-10580
CRITICAL
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
CVSS 9.8
CVE-2026-11336
MEDIUM
tittuvarghese CollegeManagementSystem Admin admin_page.php improper authorization
CVSS 6.3
CVE-2026-10876
MEDIUM
SourceCodester Ship Ferry Ticket Reservation System admin improper authorization
CVSS 6.3
CVE-2026-48579
CRITICAL
Microsoft Exchange Online Information Disclosure Vulnerability
CVSS 9.1
CVE-2026-41522
HIGH
DFIR-IRIS < 2.4.28 - GraphQL Authorization Bypass
CVE-2026-10693
MEDIUM
SourceCodester Online Boat Reservation System Administrative Endpoint improper authorization
CVSS 6.3
Details
Vulnerabilities
1,461
Exploit Likelihood
High