The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,140 vulnerabilities with CWE-862
CVE-2026-9486
MEDIUM
SourceCodester Student Grades Management System cross-site request forgery
CVSS 4.3
CVE-2026-24546
MEDIUM
WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-2651
CRITICAL
Missing Authorization Validation in mlflow/mlflow
CVSS 9.0
CVE-2026-9350
HIGH
NousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorization
CVSS 7.3
CVE-2026-9303
MEDIUM
calcom cal.diy cross-site request forgery
CVSS 4.3
CVE-2026-9284
HIGH
WooCommerce PayPal Payments <= 4.0.1 - Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure
CVSS 8.2
CVE-2026-3294
HIGH
Authentication Logic Vulnerability on Multiple TP-Link Range Extenders
CVSS 8.8
CVE-2026-39967
LOW
TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter
CVSS 3.1
CVE-2026-9255
HIGH
Tool Execution Without Authorization via Piped Stdin in Kiro CLI
CVSS 7.8
CVE-2026-33712
CRITICAL
TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls
CVSS 10.0
CVE-2026-9251
MEDIUM
Devolutions Server - Missing Authorization
CVSS 5.4
CVE-2026-9246
MEDIUM
Devolutions Server - Missing Authorization
CVSS 4.3
CVE-2026-9224
MEDIUM
Devolutions Server - Missing Authorization
CVSS 4.3
CVE-2026-9011
HIGH
Ditty <= 3.1.65 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via ditty_init AJAX Action
CVSS 7.5
CVE-2026-8692
MEDIUM
Vedrixa Forms <= 1.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Structure Modification via wefb_save_form_structure AJAX Action
CVSS 4.3
CVE-2026-8684
MEDIUM
MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action
CVSS 5.3
CVE-2026-8381
MEDIUM
Broken Access Control in TeamViewer DEX Platform (On Premises)
CVSS 5.4
CVE-2026-7249
MEDIUM
Location Weather <= 3.0.2 - Missing Authorization to Authenticated (Contributor+) Block Settings Modification and Cache Purging
CVSS 4.3
CVE-2026-44409
MEDIUM
ZTE MU5250 - Unauthorized Information Disclosure
CVSS 5.7
CVE-2026-2518
MEDIUM
FastX <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation and Activation
CVSS 4.3
CVE-2026-39833
CRITICAL
Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
CVSS 9.1
CVE-2026-39831
CRITICAL
Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
CVSS 9.1
CVE-2026-8239
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
CVSS 5.3
CVE-2026-8238
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/message_page' allowing unauthenticated read of any conversation message
CVSS 5.3
CVE-2026-8237
MEDIUM
Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
CVSS 5.3
Details
Vulnerabilities
8,140
Exploit Likelihood
High