CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,330 vulnerabilities with CWE-862
CVE-2025-48547 HIGH
Google Android - Local Privilege Escalation via Permission Bypass
CVSS 7.3
CVE-2025-48524 MEDIUM
WifiPermissionsUtil - Privilege Escalation
CVSS 5.5
CVE-2025-0076 LOW
Google Android Missing Permission Check - Information Disclosure
CVSS 3.3
CVE-2025-26450 HIGH
Android - Unauthenticated Local Privilege Escalation via Missing Permission Check in IInputMethodSessionWrapper
CVSS 7.8
CVE-2025-26445 MEDIUM
Android - Missing Authorization in ConnectivityService
CVSS 5.5
CVE-2025-26440 HIGH
Android - Unauthenticated Camera Access via CameraService Permissions Bypass
CVSS 7.8
CVE-2025-26437 MEDIUM
Android - Unauthenticated Local Information Disclosure via CredentialManagerServiceStub
CVSS 5.5
CVE-2025-8268 MEDIUM
WordPress AI Engine <2.9.5 - Info Disclosure
CVSS 6.5
CVE-2025-58639 MEDIUM
Ali Khallad Contact Form By Mega Forms <1.6.1 - Info Disclosure
CVSS 5.4
CVE-2025-58635 MEDIUM
PalsCode Support Genix <1.4.23 - Info Disclosure
CVSS 5.3
CVE-2025-58634 MEDIUM
PeachPay Payments <= 1.117.4 - Missing Authorization
CVSS 5.3
CVE-2025-58622 MEDIUM
yydevelopment Mobile Contact Line <2.4.0 - Info Disclosure
CVSS 4.3
CVE-2025-58617 MEDIUM
FAKTOR VIER F4 Media Taxonomies <1.1.4 - Info Disclosure
CVSS 4.3
CVE-2025-58616 MEDIUM
Frisbii Pay <1.8.2.1 - Info Disclosure
CVSS 6.5
CVE-2025-58613 MEDIUM
Barn2 Plugins <1.4.10 - Privilege Escalation
CVSS 5.3
CVE-2025-58606 MEDIUM
CozyThemes SaasLauncher <1.3.0 - Info Disclosure
CVSS 5.0
CVE-2025-58603 MEDIUM
Surfer <1.6.4.574 - Info Disclosure
CVSS 5.3
CVE-2025-58601 MEDIUM
RadiusTheme Classified Listing <5.0.6 - RCE
CVSS 4.3
CVE-2025-58600 MEDIUM
Cozmoslabs Paid Member Subscriptions <2.15.9 - Info Disclosure
CVSS 5.3
CVE-2025-58599 MEDIUM
Order Delivery Date for WooCommerce <4.1.0 - Info Disclosure
CVSS 4.3
CVE-2025-58594 MEDIUM
themefusecom Brizy <2.7.12 - Info Disclosure
CVSS 4.3
CVE-2025-58460 MEDIUM
Jenkins OpenTelemetry Plugin <3.1543.v8446b_92b_cd64 - SSRF
CVSS 4.2
CVE-2025-3701 MEDIUM
Malcure Malware Scanner <17 - Auth Bypass
CVSS 4.3
CVE-2025-9219 MEDIUM
Post SMTP - Unauthorized Data Modification
CVSS 4.3
CVE-2025-58210 MEDIUM
ThemeMove Makeaholic <= 1.8.5 - Missing Authorization
CVSS 5.3
Details
Vulnerabilities 8,330
Exploit Likelihood High