CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,330 vulnerabilities with CWE-862
CVE-2025-55142 HIGH
Ivanti Connect Secure <22.7R2.9,22.8R2 - Auth Bypass
CVSS 8.8
CVE-2025-55141 HIGH
Ivanti Connect Secure <22.7R2.9,22.8R2 - Auth Bypass
CVSS 8.8
CVE-2025-59017 HIGH
TYPO3 CMS 9.0.0-13.4.17 - Missing Authorization in Backend Routing
CVSS 8.8
CVE-2025-9542 MEDIUM
AutomatorWP < 5.3.7 - Authenticated Missing Authorization in Plugin Functions
CVSS 5.4
CVE-2025-42918 MEDIUM
SAP NetWeaver Application Server for ABAP - Authenticated Missing Authorization for Profile Parameters
CVSS 4.3
CVE-2025-42917 MEDIUM
SAP HCM Approve Timesheets Fiori 2.0 - Privilege Escalation
CVSS 6.5
CVE-2025-42915 MEDIUM
SAP Fiori app Manage Payment Blocks - Missing Authorization
CVSS 5.4
CVE-2025-42914 LOW
SAP HCM My Timesheet Fiori 2.0 - Privilege Escalation
CVSS 3.1
CVE-2025-42913 LOW
SAP HCM My Timesheet Fiori 2.0 - Privilege Escalation
CVSS 3.1
CVE-2025-42912 MEDIUM
SAP HCM My Timesheet Fiori 2.0 - Privilege Escalation
CVSS 6.5
CVE-2025-42911 MEDIUM
SAP NetWeaver - Authenticated Information Disclosure via Service Data Download Function Module
CVSS 5.0
CVE-2025-57817 HIGH
Fides < 2.69.1 - Missing Authorization in OAuth Client Scope Assignment
CVSS 7.2
CVE-2025-7040 HIGH
Cloud SAML SSO plugin <1.0.19 - Info Disclosure
CVSS 8.2
CVE-2025-54744 MEDIUM
Stylemix MasterStudy LMS <3.6.15 - Privilege Escalation
CVSS 6.5
CVE-2025-53571 MEDIUM
VillaTheme HAPPY <1.0.6 - Info Disclosure
CVSS 6.5
CVE-2025-58824 MEDIUM
webriti Shk Corporate <2.4.1.1 - Info Disclosure
CVSS 4.3
CVE-2025-58817 MEDIUM
DesertThemes SoftMe <1.1.24 - Info Disclosure
CVSS 4.3
CVE-2025-58816 LOW
Plugin Devs Product Carousel Slider <2.1.3 - Info Disclosure
CVSS 3.5
CVE-2025-58813 MEDIUM
Consultstreet <3.0.0 - Info Disclosure
CVSS 4.3
CVE-2025-58795 MEDIUM
Payoneer Checkout <= 3.4.0 - Content Spoofing via Missing Authorization
CVSS 4.3
CVE-2025-58785 MEDIUM
Ray Enterprise Translation <1.7.1 - Info Disclosure
CVSS 5.4
CVE-2025-58783 MEDIUM
Gutentor <= 3.5.5 - Missing Authorization
CVSS 4.3
CVE-2025-8944 MEDIUM
OceanWP < 4.1.2 - Authenticated Missing Authorization via AJAX Request Handler
CVSS 4.3
CVE-2025-22414 HIGH
Android - Missing Authorization in FrpBypassAlertActivity
CVSS 7.8
CVE-2025-48549 HIGH
Android - Unauthenticated Audio Recording via Missing Permission Check
CVSS 7.8
Details
Vulnerabilities 8,330
Exploit Likelihood High