The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,332 vulnerabilities with CWE-862
CVE-2025-32210
MEDIUM
CM Registration and Invitation Codes <2.5.2 - Info Disclosure
CVSS 6.5
CVE-2025-32208
MEDIUM
Hive Support <1.2.2 - Info Disclosure
CVSS 6.5
CVE-2025-3417
HIGH
Embedder plugin <1.3.5 - Privilege Escalation
CVSS 8.8
CVE-2025-2719
MEDIUM
Swatchly - WooCommerce Variation Swatches - Info Disclosure
CVSS 6.5
CVE-2025-26901
MEDIUM
Brizy Pro <= 2.6.1 - Missing Authorization
CVSS 4.3
CVE-2025-26888
MEDIUM
WooCommerce Multilingual & Multicurrency <5.3.8 - Info Disclosure
CVSS 5.3
CVE-2025-32684
MEDIUM
RomanCode MapSVG Lite <8.5.32 - Info Disclosure
CVSS 5.0
CVE-2025-32624
HIGH
Czater.pl - Live Chat <1.0.5 - CSRF
CVSS 7.1
CVE-2025-31377
HIGH
Asaquzzaman mishu Woo Product Feed For Marketing Channels <1.9.0 - ...
CVSS 7.5
CVE-2025-31042
MEDIUM
Sandwich Adsense <4.0.2 - Info Disclosure
CVSS 5.3
CVE-2025-31012
MEDIUM
Phil Age Gate <3.5.4 - Info Disclosure
CVSS 5.3
CVE-2025-31004
MEDIUM
Croover.inc Rich Table of Contents <1.4.0 - Info Disclosure
CVSS 4.3
CVE-2025-32279
MEDIUM
Shahjada Live Forms <4.8.5 - Info Disclosure
CVSS 4.3
CVE-2025-2876
MEDIUM
MelaPress Login Security < 2.1.1 - Unauthenticated Arbitrary User Deletion via Missing Capability Check
CVSS 5.3
CVE-2025-2568
MEDIUM
Vayu Blocks 1.0.4-1.2.1 - Unauthenticated Data Access/Modification via Missing Capability Checks
CVSS 5.3
CVE-2025-3437
MEDIUM
Motors Plugin <= 1.4.66 - Authenticated Data Modification via Missing Capability Check
CVSS 4.3
CVE-2025-2807
HIGH
Motors Plugin <= 1.4.64 - Authenticated Arbitrary Plugin Installation
CVSS 8.8
CVE-2025-30017
MEDIUM
SAP Solution Manager 7.1 - Auth Bypass
CVSS 4.4
CVE-2025-27437
MEDIUM
SAP NetWeaver Application Server ABAP - Info Disclosure
CVSS 4.3
CVE-2025-27435
MEDIUM
SAP Commerce Cloud HY_COM 2205 and COM_CLOUD 2211 - Unauthenticated Coupon Code Exposure via URL Parameters
CVSS 4.2
CVE-2025-27428
HIGH
SAP Solution Manager - Path Traversal
CVSS 7.7
CVE-2025-26657
MEDIUM
SAP KMC WPC >=7.50 - Unauthenticated Username Disclosure via Parameter Query
CVSS 5.3
CVE-2025-31171
MEDIUM
HarmonyOS - Missing Authorization in Kernel File System Module
CVSS 6.8
CVE-2025-2789
MEDIUM
MultiVendorX < 4.2.19 - Unauthenticated Table Rate Shipping Row Deletion
CVSS 5.3
CVE-2025-1233
MEDIUM
Lafka Plugin <7.1.0 - Privilege Escalation
CVSS 4.3
Details
Vulnerabilities
8,332
Exploit Likelihood
High