The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,261 vulnerabilities with CWE-862
CVE-2026-23477
HIGH
Rocket.Chat <6.12.0 - Info Disclosure
CVSS 7.7
CVE-2026-0635
MEDIUM
Responsive Accordion Slider <1.2.2 - Info Disclosure
CVSS 4.3
CVE-2026-0511
HIGH
SAP Fiori App - Privilege Escalation
CVSS 8.1
CVE-2026-0506
HIGH
SAP NetWeaver Application Server ABAP - Authenticated Missing Authorization Check via RFC Function
CVSS 8.1
CVE-2026-0503
MEDIUM
SAP ERP Central Component and SAP S/4HANA (SAP EHS Management) - Missing Authorization Check
CVSS 6.4
CVE-2026-0497
MEDIUM
SAP Product Designer Web UI - Info Disclosure
CVSS 4.3
CVE-2026-0817
MEDIUM
MediaWiki CampaignEvents 1.39, 1.43-1.45 - Missing Authorization
CVSS 5.3
CVE-2026-22522
MEDIUM
Munir Kamal Block Slider <2.2.3 - Privilege Escalation
CVSS 6.5
CVE-2026-22517
MEDIUM
GA4WP: Google Analytics for WordPress <2.10.0 - Auth Bypass
CVSS 5.4
CVE-2026-22492
MEDIUM
Nawawi Jamili Docket Cache <24.07.04 - Info Disclosure
CVSS 4.3
CVE-2026-22490
MEDIUM
WordPress LPagery <= 2.4.9 - Missing Authorization Access Control Bypass
CVSS 5.4
CVE-2026-22488
MEDIUM
IdeaBox Creations Dashboard Welcome <1.0.8 - Info Disclosure
CVSS 5.3
CVE-2026-22487
MEDIUM
baqend Speed Kit <2.0.2 - Info Disclosure
CVSS 4.3
CVE-2026-22486
MEDIUM
Hakob Re Gallery & Responsive Photo Gallery Plugin <1.17.18 - RCE
CVSS 5.3
CVE-2026-0676
MEDIUM
G5Theme Zorka <= 1.5.7 - Info Disclosure
CVSS 5.3
CVE-2026-0674
MEDIUM
Campaign Monitor for WordPress <2.9.0 - RCE
CVSS 4.3
CVE-2026-0656
HIGH
iPaymu Payment Gateway <2.0.2 - Missing Authentication
CVSS 8.2
CVE-2026-0628
HIGH
Google Chrome < 143.0.7499.192 - Insufficient Policy Enforcement in WebView Tag
CVSS 8.8
CVE-2026-21429
MEDIUM
emlog 2.5.23 - Missing Authorization
CVSS 4.3
CVE-2025-69189
HIGH
WordPress JobBank plugin <= 1.2.3 - Broken Access Control vulnerability
CVSS 7.3
CVE-2025-69137
MEDIUM
WordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerability
CVSS 6.5
CVE-2025-69103
HIGH
WordPress Brikk theme <= 3.0.0 - Arbitrary Content Deletion vulnerability
CVSS 7.5
CVE-2025-48640
HIGH
Android - Missing Permission Check for 3rd Party Passkey Pairing Approval
CVSS 8.0
CVE-2025-48617
HIGH
Android - Local Privilege Escalation via CarrierConfigLoader Permissions Bypass
CVSS 7.8
CVE-2025-14272
HIGH
Rockwell Automation FactoryTalk Analytics PavilionX
Details
Vulnerabilities
8,261
Exploit Likelihood
High