The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,331 vulnerabilities with CWE-862
CVE-2025-4520
MEDIUM
Uncanny Automator < 6.4.0.2 - Authenticated Data Modification via Missing Capability Check
CVSS 5.4
CVE-2025-4339
MEDIUM
TheGem <= 5.10.3 - Authenticated Arbitrary Theme Options Update via ajaxApi() Missing Capability Check
CVSS 4.3
CVE-2025-43011
HIGH
SAP Landscape Transformation - Privilege Escalation
CVSS 7.7
CVE-2025-43009
MEDIUM
SAP Service Parts Management (SPM) - Missing Authorization
CVSS 6.3
CVE-2025-43008
MEDIUM
SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal - Unauthenticated Information Disclosure via Missing Authorization
CVSS 5.8
CVE-2025-43007
MEDIUM
SAP Service Parts Management (SPM) - Authenticated Privilege Escalation via Missing Authorization
CVSS 6.3
CVE-2025-43004
MEDIUM
Production Operator Dashboards - Info Disclosure
CVSS 5.3
CVE-2025-43000
HIGH
Promotion Management Wizard - Info Disclosure
CVSS 7.9
CVE-2025-30448
CRITICAL
iPadOS < 17.7.7 - Unauthenticated iCloud Folder Sharing Enablement
CVSS 9.1
CVE-2025-46745
MEDIUM
SEL Blueframe OS < 1.12.0 - Authenticated Missing Authorization
CVSS 6.5
CVE-2025-26846
CRITICAL
Znuny 6.0.0-6.0.48 - Missing Authorization in Generic Interface Ticket Metadata Update
CVSS 9.8
CVE-2025-3876
HIGH
SMS Alert Order Notifications < 3.8.1 - Authenticated Privilege Escalation via Insufficient OTP Validation
CVSS 8.8
CVE-2025-28202
HIGH
Victure RX1800 EN_V1.0.0_r12_110933 - Unauthenticated SSH and Telnet Service Enablement
CVSS 8.8
CVE-2025-3949
MEDIUM
Website Builder by SeedProd < 6.18.15 - Authenticated Unauthorized Data Access via seedprod_lite_get_revisisons Function
CVSS 4.3
CVE-2025-20164
HIGH
Cisco Industrial Ethernet Switch Device Manager - Privilege Escalation
CVSS 8.3
CVE-2025-47692
MEDIUM
ContentStudio <1.3.3 - Info Disclosure
CVSS 4.3
CVE-2025-47688
MEDIUM
Advanced File Manager <= 5.3.1 - Missing Authorization
CVSS 5.3
CVE-2025-47628
MEDIUM
quomodosoft QS Dark Mode <= 3.0 - Missing Authorization
CVSS 5.4
CVE-2025-47612
MEDIUM
ClickWhale <= 2.4.6 - Missing Authorization
CVSS 5.4
CVE-2025-47602
MEDIUM
Calculate Prices based on Distance For WooCommerce <= 1.3.5 - Missing Authorization
CVSS 5.4
CVE-2025-47591
MEDIUM
CreedAlly Bulk Featured Image <1.2.1 - RCE
CVSS 4.3
CVE-2025-47528
MEDIUM
Ovation Elements <1.1.2 - Info Disclosure
CVSS 4.3
CVE-2025-47526
MEDIUM
GS Variation Swatches for WooCommerce <3.0.4 - Info Disclosure
CVSS 5.4
CVE-2025-47486
MEDIUM
CyberChimps Gutenberg & Elementor Templates Importer For Responsive...
CVSS 5.3
CVE-2025-47485
MEDIUM
CozyBlocks <2.1.22 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
8,331
Exploit Likelihood
High