The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
7,700 vulnerabilities with CWE-862
CVE-2026-40742
MEDIUM
WordPress Nelio AB Testing plugin <= 8.2.8 - Sensitive Data Exposure vulnerability
CVSS 5.3
CVE-2026-40740
MEDIUM
WordPress Tutor LMS plugin <= 3.9.7 - Broken Access Control vulnerability
CVSS 5.4
CVE-2026-40730
MEDIUM
WordPress ThemeGrill Demo Importer plugin <= 2.0.0.6 - Broken Access Control vulnerability
CVSS 5.3
CVE-2026-40729
MEDIUM
WordPress 3D viewer – Embed 3D Models plugin <= 1.8.5 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-40728
MEDIUM
WordPress Magazine Blocks plugin <= 1.8.3 - Broken Access Control vulnerability
CVSS 4.3
CVE-2026-27769
LOW
Connected Workspaces: Malicious remote server can manipulate arbitrary user's status
CVSS 2.7
CVE-2026-3649
MEDIUM
Katalogportal-pdf-sync Widget <= 1.0.0 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure via 'katalogportal_shortcodePrinter' AJAX Action
CVSS 5.3
CVE-2026-3642
MEDIUM
e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX
CVSS 5.3
CVE-2026-4812
MEDIUM
Advanced Custom Fields (ACF®) <= 6.7.0 - Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters
CVSS 5.3
CVE-2026-1314
MEDIUM
3D FlipBook < 1.16.17 - Information Exposure
CVSS 5.3
CVE-2026-35033
CRITICAL
Jellyfin: Potential SSRF + Arbitrary file read via stream argument injection
CVSS 9.1
CVE-2026-4109
MEDIUM
Eventin < 4.1.8 - Information Exposure
CVSS 4.3
CVE-2026-4365
CRITICAL
LearnPress <= 4.3.2.8 - Missing Authorization to Unauthenticated Arbitrary Quiz Answer Deletion
CVSS 9.1
CVE-2026-34261
MEDIUM
Missing Authorization check in SAP Business Analytics and SAP Content Management
CVSS 6.5
CVE-2026-34256
HIGH
Missing Authorization check in SAP ERP and SAP S/4 HANA (Private Cloud and On-Premise)
CVSS 7.1
CVE-2026-27679
MEDIUM
Missing Authorization check in SAP S/4HANA Frontend OData Service (Manage Reference Structures)
CVSS 6.5
CVE-2026-27678
MEDIUM
Missing Authorization check in SAP S/4HANA Backend OData Service (Manage Reference Structures)
CVSS 6.5
CVE-2026-27677
MEDIUM
Missing Authorization check in SAP S/4HANA OData Service (Manage Reference Equipment)
CVSS 6.5
CVE-2026-27676
MEDIUM
Missing Authorization check in SAP S/4HANA OData Service (Manage Technical Object Structures)
CVSS 4.3
CVE-2026-27673
MEDIUM
Missing Authorization Check in SAP S/4HANA (Private Cloud and On-Premise)
CVSS 4.9
CVE-2026-27672
MEDIUM
Missing Authorization check in Material Master Application
CVSS 4.3
CVE-2026-32270
LOW
Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments
CVE-2026-6109
MEDIUM
FoundationAgents MetaGPT Mineflayer HTTP API index.js evaluateCode cross-site request forgery
CVSS 4.3
CVE-2026-3358
MEDIUM
Tutor LMS <= 3.9.7 - Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment
CVSS 5.4
CVE-2026-40189
CRITICAL
goshs has a file-based ACL authorization bypass in goshs state-changing routes
CVSS 9.8
Details
Vulnerabilities
7,700
Exploit Likelihood
High