The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,330 vulnerabilities with CWE-862
CVE-2025-11692
MEDIUM
Zip Attachments plugin <1.7 - Info Disclosure
CVSS 5.3
CVE-2025-10648
MEDIUM
YourMembership YM SSO Login <1.1.7 - Info Disclosure
CVSS 5.3
CVE-2025-10313
HIGH
Find And Replace content for WordPress <= 1.1 - Unauthenticated Stored XSS and Arbitrary Content Replacement
CVSS 7.2
CVE-2025-10303
MEDIUM
Library Management System <3.1 - Info Disclosure
CVSS 4.3
CVE-2025-10299
HIGH
WPBifröst Plugin <1.0.7 - Privilege Escalation
CVSS 8.8
CVE-2025-10186
MEDIUM
WhyDonate <= 4.0.15 - Unauthenticated Data Deletion via remove_row
CVSS 5.3
CVE-2025-33182
HIGH
NVIDIA Jetson Linux - Privilege Escalation
CVSS 7.6
CVE-2025-10732
MEDIUM
WordPress SureForms <1.12.2 - Info Disclosure
CVSS 4.3
CVE-2025-8682
MEDIUM
Newsup theme <5.0.10 - Unauth Plugin Install
CVSS 4.3
CVE-2025-8593
HIGH
GSheetConnector For Gravity Forms <1.3.27 - Auth Bypass
CVSS 8.8
CVE-2025-11380
MEDIUM
Everest Backup - WordPress Cloud Backup, Migration, Restore & Cloni...
CVSS 5.9
CVE-2025-9549
MEDIUM
Drupal Facets <2.0.10-3.0.1 - Forceful Browsing
CVSS 6.5
CVE-2025-11581
MEDIUM
PowerJob < 5.1.2 - Missing Authorization in OpenAPIController
CVSS 5.3
CVE-2025-11580
MEDIUM
PowerJob < 5.1.2 - Unauthenticated Missing Authorization in /user/list Endpoint
CVSS 5.3
CVE-2025-8887
MEDIUM
Usta Information Systems Inc. Aybs Interaktif - Info Disclosure
CVSS 6.1
CVE-2025-8886
MEDIUM
Usta Information Systems Inc. Aybs Interaktif - Privilege Escalation
CVSS 6.7
CVE-2025-59968
HIGH
Juniper Space Security Director < 24.1R3 Patch V4 - Unauthenticated Metadata Read and Modify via Web Interface
CVSS 8.6
CVE-2025-10352
CRITICAL
Melis Platform < 5.3.11 - Unauthenticated Administrator Account Creation via ToolUser Endpoint
CVE-2025-11442
MEDIUM
JhumanJ OpnForm < 1.9.3 - Cross-Site Request Forgery via API Endpoint
CVSS 4.3
CVE-2025-11439
MEDIUM
JhumanJ OpnForm <1.9.3 - Auth Bypass
CVSS 4.3
CVE-2025-11438
MEDIUM
JhumanJ OpnForm <1.9.3 - Auth Bypass
CVSS 6.3
CVE-2025-9243
HIGH
WordPress Cost Calculator Builder <3.5.32 - Info Disclosure
CVSS 8.1
CVE-2025-9029
MEDIUM
WDesignKit <= 1.2.16 - Unauthenticated Missing Authorization via wdkit_handle_review_submission
CVSS 4.3
CVE-2025-11228
MEDIUM
GiveWP - Donation Plugin - Info Disclosure
CVSS 5.3
CVE-2025-9194
MEDIUM
Constructor Theme <1.6.5 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities
8,330
Exploit Likelihood
High