The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,331 vulnerabilities with CWE-862
CVE-2025-21416
HIGH
Azure Virtual Desktop - Missing Authorization
CVSS 8.5
CVE-2025-32973
CRITICAL
XWiki 15.9-15.10.12, 16.0.0-16.4.3, 16.5.0-16.8.0-rc-1 - Missing Authorization for Programming Rights
CVSS 9.0
CVE-2025-3953
MEDIUM
WP Statistics < 14.13.3 - Authenticated Arbitrary Plugin Settings Update via optionUpdater Function
CVSS 5.4
CVE-2025-46348
CRITICAL
YesWiki < 4.5.4 - Unauthenticated Backup Archive Creation and Download
CVSS 10.0
CVE-2025-4095
MEDIUM
Registry Access Management - Info Disclosure
CVE-2025-4064
MEDIUM
ScriptAndTools Online-Travling-System 1.0 - Improper Access Control in /admin/viewenquiry.php
CVSS 5.3
CVE-2025-3452
MEDIUM
SecuPress Free < 2.3.9 - Authenticated Arbitrary Plugin Installation via Missing Capability Check
CVSS 4.3
CVE-2025-39367
MEDIUM
SeventhQueen Kleo <5.4.4 - Info Disclosure
CVSS 5.3
CVE-2025-3997
MEDIUM
dazhouda lecms 3.0.3 - Cross-Site Request Forgery via Personal Information Page
CVSS 4.3
CVE-2025-3981
MEDIUM
wowjoy Internet Doctor Workstation System 1.0 - Info Disclosure
CVSS 4.3
CVE-2025-3980
MEDIUM
wowjoy Internet Doctor Workstation System 1.0 - Auth Bypass
CVSS 4.3
CVE-2025-3979
MEDIUM
lecms 3.0.3 - Cross-Site Request Forgery in Password Change Handler
CVSS 4.3
CVE-2025-3977
MEDIUM
iteachyou Dreamer CMS <4.1.3 - Info Disclosure
CVSS 4.3
CVE-2025-3964
MEDIUM
withstars Books-Management-System 1.0 - CSRF
CVSS 4.3
CVE-2025-3963
HIGH
withstars Books-Management-System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-3960
HIGH
withstars Books-Management-System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-3959
MEDIUM
withstars Books-Management-System 1.0 - CSRF
CVSS 4.3
CVE-2025-3915
MEDIUM
Aeropage Sync for Airtable <3.2.0 - Info Disclosure
CVSS 4.3
CVE-2025-3906
HIGH
Integração entre Eduzz e Woocommerce - Privilege Escalation
CVSS 8.8
CVE-2025-43862
HIGH
Dify < 0.6.12 - Improper Access Control in APP Orchestration
CVSS 7.6
CVE-2025-32045
MEDIUM
Moodle < 4.1.17 - Missing Authorization in Grade Reports
CVSS 5.3
CVE-2025-3912
MEDIUM
WS Form LITE <= 1.10.35 - Unauthenticated Sensitive Data Exposure
CVSS 5.3
CVE-2025-1279
HIGH
BM Content Builder plugin - Privilege Escalation
CVSS 8.8
CVE-2025-46535
MEDIUM
AlphaEfficiencyTeam Custom Login and Registration <1.0.0 - RCE
CVSS 5.4
CVE-2025-46519
MEDIUM
Media Library Downloader <1.3.1 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities
8,331
Exploit Likelihood
High