The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,344 vulnerabilities with CWE-862
CVE-2025-0935
MEDIUM
Media Library Folders <= 8.3.0 - Authenticated Plugin Settings Change via Missing Capability Check
CVSS 4.3
CVE-2025-24692
HIGH
Michael Revellin-Clerc Bulk Menu Edit <1.3 - RCE
CVSS 7.1
CVE-2025-24607
MEDIUM
IdeaPush <= 8.71 - Missing Authorization
CVSS 5.8
CVE-2025-23771
MEDIUM
Murali Push Notification <2.11 - RCE
CVSS 6.5
CVE-2025-23766
MEDIUM
OPSI Israel Domestic Shipments <2.6.6 - Info Disclosure
CVSS 6.5
CVE-2025-23534
MEDIUM
WPLingo <= 1.1.2 - Unauthenticated Arbitrary Content Deletion via Missing Authorization
CVSS 6.5
CVE-2025-22702
MEDIUM
EPC Photography <7.5.2 - Info Disclosure
CVSS 6.3
CVE-2025-22698
MEDIUM
Ability, Inc Accessibility Suite <4.16 - RCE
CVSS 6.3
CVE-2025-1214
MEDIUM
PiHome maxair - Missing Authorization in Role-Based Access Control via /user_accounts.php?uid
CVSS 6.3
CVE-2025-26378
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Password Reset via Crafted HTTP Requests
CVSS 8.8
CVE-2025-26377
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated User Removal via Crafted HTTP Requests
CVSS 8.1
CVE-2025-26376
MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated User Data Modification via Crafted HTTP Requests
CVSS 6.5
CVE-2025-26375
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Privilege Escalation via User Creation
CVSS 8.8
CVE-2025-26374
MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated User Enumeration via Users Endpoint
CVSS 6.5
CVE-2025-26373
MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated User Enumeration via User Endpoint
CVSS 6.5
CVE-2025-26372
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated User Removal from Groups via Crafted HTTP Requests
CVSS 7.1
CVE-2025-26371
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Missing Authorization in User-Groups Routes
CVSS 8.8
CVE-2025-26370
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Privilege Removal via User Groups Route
CVSS 7.1
CVE-2025-26369
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Privilege Escalation via User Group Route
CVSS 8.8
CVE-2025-26368
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated User Group Removal via Crafted HTTP Requests
CVSS 8.1
CVE-2025-26367
MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated Arbitrary User Group Creation via HTTP Request
CVSS 4.3
CVE-2025-0526
MEDIUM
Octopus Server 2022.4.791-2024.3.13097 - Unauthenticated Arbitrary File Write via API Endpoint
CVSS 5.4
CVE-2025-25241
MEDIUM
SAP Fiori Apps Reference Library (My Overtime Requests) >=GBX01HR5 605 - Missing Authorization
CVSS 5.4
CVE-2025-23190
MEDIUM
SAP NetWeaver and ABAP Platform ST-PI - Missing Authorization Check
CVSS 4.3
CVE-2025-23189
MEDIUM
SAP NetWeaver and ABAP Platform (SDCCN) - Authenticated Missing Authorization in SDCCN Transaction
CVSS 4.3
Details
Vulnerabilities
8,344
Exploit Likelihood
High