The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,330 vulnerabilities with CWE-862
CVE-2025-10305
MEDIUM
Secure Passkeys plugin <1.2.1 - Auth Bypass
CVSS 5.3
CVE-2025-7665
HIGH
Miniorange OTP Verification with Firebase plugin <3.6.2 - Privilege...
CVSS 8.1
CVE-2025-8487
MEDIUM
Kubio AI Page Builder <2.6.3 - Privilege Escalation
CVSS 5.4
CVE-2025-10690
CRITICAL
Goza - Nonprofit Charity WordPress Theme <3.2.2 - RCE
CVSS 9.8
CVE-2025-8565
HIGH
WP Legal Pages <3.4.3 - Privilege Escalation
CVSS 8.1
CVE-2025-59353
HIGH
Dragonfly < 2.1.0 - Improper Certificate Validation via mTLS Authentication Bypass
CVSS 7.5
CVE-2025-59416
HIGH
tsc-web-client < 1.2 - Unauthenticated Missing Authorization via Fork API
CVE-2025-59475
MEDIUM
Jenkins < 2.516.3 and < 2.528 - Missing Authorization in User Profile Dropdown Menu
CVSS 4.3
CVE-2025-59474
MEDIUM
Jenkins < 2.516.3 and < 2.528 - Missing Authorization for Agent Name Listing via Sidepanel Executors Widget
CVSS 5.3
CVE-2025-8999
MEDIUM
Sydney WordPress <2.56 - Privilege Escalation
CVSS 5.3
CVE-2025-43805
MEDIUM
Liferay Portal 7.3.0-7.4.3.111 & DXP Unauthenticated Display Page Template Access
CVSS 5.3
CVE-2025-8446
MEDIUM
Blaze Demo Importer <1.0.12 - Privilege Escalation
CVSS 4.3
CVE-2025-43358
HIGH
macOS Sonoma <14.8 - Privilege Escalation
CVSS 8.8
CVE-2025-43341
HIGH
macOS Sonoma <14.8 - Privilege Escalation
CVSS 7.8
CVE-2025-43331
MEDIUM
macOS < 26.0 - Unprotected User Data Exposure via Downgrade Issue
CVSS 4.0
CVE-2025-43329
HIGH
tvOS 26-iOS 26-iPadOS 26-watchOS 26 - Privilege Escalation
CVSS 8.8
CVE-2025-43318
MEDIUM
macOS < 26 - Unauthorized Private Information Access via Missing Entitlement Checks
CVSS 6.2
CVE-2025-43316
HIGH
visionOS <26 - Privilege Escalation
CVSS 7.8
CVE-2025-43311
MEDIUM
macOS < 14.8, < 15.7, < 26 - Unprotected User Data Exposure via Missing Authorization
CVSS 5.1
CVE-2025-43286
HIGH
macOS <14.8-15.7 - Privilege Escalation
CVSS 7.8
CVE-2025-9076
MEDIUM
Mattermost <10.10.2 - Info Disclosure
CVSS 6.5
CVE-2025-43788
MEDIUM
Liferay Portal 7.4.0-7.4.3.124 & DXP 2024.Q1.1-2024.Q1.12 - Auth Missing in Org Selector
CVSS 4.3
CVE-2025-9018
HIGH
Time Tracker plugin <3.1.0 - Privilege Escalation
CVSS 8.8
CVE-2025-8492
MEDIUM
Salon Booking System <10.20 - Info Disclosure
CVSS 5.3
CVE-2025-8425
HIGH
My WP Translate <1.2 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities
8,330
Exploit Likelihood
High