CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,333 vulnerabilities with CWE-862
CVE-2025-31757 MEDIUM
BinaryCarpenter Free Woocommerce Product Table View <1.78 - RCE
CVSS 5.4
CVE-2025-31755 MEDIUM
pCloud Backup <1.0.1 - Info Disclosure
CVSS 4.3
CVE-2025-31752 MEDIUM
Bulk Fields Editor <= 1.8.0 - Missing Authorization
CVSS 4.3
CVE-2025-31732 MEDIUM
GB Gallery Slideshow <1.3 - Info Disclosure
CVSS 4.3
CVE-2025-31408 MEDIUM
Zoho Flow <2.13.4 - Privilege Escalation
CVSS 4.3
CVE-2025-31415 HIGH
YayCommerce YayExtra <1.5.2 - Info Disclosure
CVSS 7.6
CVE-2025-30926 MEDIUM
KingAddons.com King Addons for Elementor - Info Disclosure
CVSS 4.3
CVE-2025-30880 HIGH
JoomSky JS Help Desk <= 2.9.2 - Missing Authorization
CVSS 7.5
CVE-2025-30797 HIGH
bigdrop.gr Greek Multi Tool <2.3.1 - Info Disclosure
CVSS 7.5
CVE-2025-3037 MEDIUM
yzk2356911358 StudentServlet-JSP - CSRF
CVSS 4.3
CVE-2025-31194 CRITICAL
macOS < 13.7.5, < 14.7.5, < 15.4 - Unauthenticated Privilege Escalation via Shortcut Execution
CVSS 9.8
CVE-2025-31182 CRITICAL
iPadOS < 18.4 - Unauthorized File Deletion via Symlink Handling
CVSS 9.8
CVE-2025-30461 CRITICAL
macOS Sequoia <15.4 - Info Disclosure
CVSS 9.8
CVE-2025-24259 CRITICAL
macOS 13.0-13.7.4, 14.0-14.7.4, 15.0-15.3 - Missing Authorization for Safari Bookmarks Access
CVSS 9.8
CVE-2025-24249 CRITICAL
macOS < 13.7.5, 14.7.5, 15.4 - Unauthorized File Path Existence Check
CVSS 9.8
CVE-2025-24245 CRITICAL
macOS < 15.4 - Unauthorized Password Access via Verification Code Delay Bypass
CVSS 9.8
CVE-2025-24181 CRITICAL
macOS < 13.7.5, < 14.7.5, < 15.4 - Unprotected User Data Exposure via Permissions Issue
CVSS 9.8
CVE-2025-31691 CRITICAL
Drupal OAuth2 Server <2.1.0 - Info Disclosure
CVSS 9.8
CVE-2025-31686 HIGH
Drupal Open Social <12.3.11-12.4.10 - Forceful Browsing
CVSS 8.1
CVE-2025-31685 CRITICAL
Drupal Open Social <12.3.11-12.4.10 - Forceful Browsing
CVSS 9.1
CVE-2025-31681 CRITICAL
Drupal Authenticator Login <2.0.6 - Forceful Browsing
CVSS 9.8
CVE-2025-31678 HIGH
Drupal AI <1.0.3 - Forceful Browsing
CVSS 8.2
CVE-2025-31618 MEDIUM
Jaap Jansma Connector to CiviCRM <1.0.9 - Privilege Escalation
CVSS 5.3
CVE-2025-31611 MEDIUM
Shaharia Azam Auto Post After Image Upload <1.6 - RCE
CVSS 4.3
CVE-2025-31609 MEDIUM
Arni Cinco WPCargo Track & - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 8,333
Exploit Likelihood High