The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,330 vulnerabilities with CWE-862
CVE-2025-22439
HIGH
Android - Missing Authorization in ActionHandler onLastAccessedStackLoaded
CVSS 7.3
CVE-2025-6685
HIGH
ATEN eco DC < 1.2.116 - Authenticated Privilege Escalation via Missing Authorization
CVSS 8.8
CVE-2025-9747
MEDIUM
Koillection < 1.7.0 - Cross-Site Request Forgery in CSRF Protection Controller
CVSS 4.3
CVE-2025-54943
CRITICAL
SUNNET Corporate Training Management System < 10.11 - Missing Authorization for Application Deployment
CVSS 9.8
CVE-2025-43773
CRITICAL
Liferay Portal 7.4.0-7.4.3.132 and Liferay DXP 2024.Q1.1-2024.Q1.18 - Missing Authorization via expandoTableLocalService
CVSS 9.1
CVE-2025-58334
HIGH
JetBrains IDE Services <2025.5.0.1086 - Privilege Escalation
CVSS 8.1
CVE-2025-54734
MEDIUM
B Slider <= 1.1.30 - Missing Authorization
CVSS 5.8
CVE-2025-54733
MEDIUM
Miles All Bootstrap Blocks <1.3.28 - RCE
CVSS 6.5
CVE-2025-54714
HIGH
Dylan James Zephyr Project Manager <3.3.201 - Info Disclosure
CVSS 7.1
CVE-2025-54710
HIGH
bPlugins Tiktok Feed <1.0.21 - Info Disclosure
CVSS 7.1
CVE-2025-53337
MEDIUM
Ashan Perera LifePress <2.1.3 - Info Disclosure
CVSS 5.4
CVE-2025-53230
HIGH
Page Manager for Elementor <2.0.5 - Privilege Escalation
CVSS 7.6
CVE-2025-48350
MEDIUM
Neuralabz LTD AutoWP <2.2.2 - Info Disclosure
CVSS 4.3
CVE-2025-48327
MEDIUM
inkthemes WP Mailgun SMTP <1.0.7 - Info Disclosure
CVSS 5.3
CVE-2025-7956
MEDIUM
Ajax Search Lite <4.13.1 - Info Disclosure
CVSS 5.3
CVE-2025-0951
MEDIUM
WordPress by LiquidThemes - Privilege Escalation
CVSS 4.3
CVE-2025-2246
MEDIUM
GitLab < 18.1.5, 18.2 < 18.2.5, 18.3 < 18.3.1 - Unauthenticated Sensitive CI/CD Variable Exposure via GraphQL API
CVSS 5.8
CVE-2025-58201
MEDIUM
AfterShip <1.17.17 - Info Disclosure
CVSS 5.3
CVE-2025-58198
MEDIUM
Xpro Theme Builder <1.2.9 - Info Disclosure
CVSS 6.5
CVE-2025-58193
MEDIUM
Uncanny Automator <6.7.0.1 - Info Disclosure
CVSS 4.3
CVE-2025-58192
MEDIUM
WP Bulk Delete <= 1.3.6 - Missing Authorization
CVSS 4.3
CVE-2025-0086
MEDIUM
AccountManagerService - Info Disclosure
CVSS 6.2
CVE-2025-48108
MEDIUM
Mojoomla School Management <93.2.0 - Info Disclosure
CVSS 6.5
CVE-2025-7828
MEDIUM
WP Filter & Combine RSS Feeds <0.5 - Info Disclosure
CVSS 4.3
CVE-2025-7827
MEDIUM
Ni WooCommerce Customer Product Report <1.2.4 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities
8,330
Exploit Likelihood
High