The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,331 vulnerabilities with CWE-862
CVE-2025-48116
MEDIUM
EventON <= 2.4.4 - Missing Authorization
CVSS 5.3
CVE-2025-48079
MEDIUM
Metagauss ProfileGrid <5.9.5.1 - Info Disclosure
CVSS 4.3
CVE-2025-47564
MEDIUM
ashanjay EventON <= 4.9.8 - Missing Authorization
CVSS 5.3
CVE-2025-47563
MEDIUM
villatheme CURCY <2.3.7 - Info Disclosure
CVSS 5.3
CVE-2025-47560
MEDIUM
MapSVG < 8.6.13 - Missing Authorization
CVSS 5.0
CVE-2025-47556
MEDIUM
QuanticaLabs CSS3 Compare Pricing Tables <11.5 - Info Disclosure
CVSS 5.4
CVE-2025-47534
MEDIUM
ValvePress Wordpress Auto Spinner <3.25.0 - Info Disclosure
CVSS 4.3
CVE-2025-39511
MEDIUM
ValvePress Pinterest Automatic Pin <4.18.2 - Info Disclosure
CVSS 4.3
CVE-2025-39493
MEDIUM
ValvePress Rankie < 1.8.2 - Missing Authorization
CVSS 4.3
CVE-2025-39482
MEDIUM
imithemes Eventer < 3.11.4 - Missing Authorization
CVSS 4.3
CVE-2025-32296
MEDIUM
quantumcloud Simple Link Directory Pro <14.7.3 - Info Disclosure
CVSS 5.3
CVE-2025-32295
MEDIUM
WordPresschef Salon Booking Pro <10.10.2 - RCE
CVSS 4.3
CVE-2025-31923
MEDIUM
QuanticaLabs CSS3 Accordions <3.0 - Info Disclosure
CVSS 5.4
CVE-2025-31630
MEDIUM
The Business <1.6.1 - Info Disclosure
CVSS 5.3
CVE-2025-31071
MEDIUM
HotStar - Multi-Purpose Business Theme <1.4 - Info Disclosure
CVSS 5.3
CVE-2025-31066
MEDIUM
themeton Acerola <= 1.6.5 - Missing Authorization
CVSS 5.3
CVE-2025-31065
MEDIUM
Rozario < 1.4 - Missing Authorization
CVSS 5.3
CVE-2025-31063
MEDIUM
redqteam Wishlist <2.1.0 - Info Disclosure
CVSS 4.3
CVE-2025-47792
MEDIUM
Nextcloud Desktop < 3.15.0 - Unauthenticated Improper Access Control via Socket API
CVSS 5.0
CVE-2025-3624
MEDIUM
Hitachi Ops Center Analyzer <11.0.4.00 - Info Disclosure
CVSS 4.3
CVE-2025-47580
MEDIUM
Front End Users <= 3.2.35 - Missing Authorization
CVSS 5.4
CVE-2025-47887
MEDIUM
Jenkins Cadence vManager < 4.0.1-286.v9e25a_740b_a_48 - Missing Authorization
CVSS 4.3
CVE-2025-47709
MEDIUM
miniorange_2fa 5.0.0-5.2.0 - Missing Authorization
CVSS 6.5
CVE-2025-24021
MEDIUM
iTop < 2.7.12 - Authenticated Missing Authorization
CVSS 5.0
CVE-2025-4430
HIGH
EZD RP < 20.19 - Unauthenticated File Manipulation via Token Endpoint
Details
Vulnerabilities
8,331
Exploit Likelihood
High