The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,324 vulnerabilities with CWE-862
CVE-2025-41343
HIGH
canaldenuncia.app < 4.4.8 - Unauthenticated Information Disclosure via Email Parameter
CVSS 7.5
CVE-2025-41342
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via id_user Parameter
CVSS 7.5
CVE-2025-41341
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via id_denuncia and seguro Parameters
CVSS 7.5
CVE-2025-41340
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via id_tp_denuncia and id_sociedad Parameters
CVSS 7.5
CVE-2025-41339
HIGH
CanalDenuncia.app < 4.4.8 - Unauthenticated Missing Authorization via id_sociedad Parameter
CVSS 7.5
CVE-2025-41338
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via id_denuncia and id_user Parameters
CVSS 7.5
CVE-2025-41337
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via web Parameter in buscarSSOParametros.php
CVSS 7.5
CVE-2025-41336
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via web Parameter in buscarConfiguracionParametros.php
CVSS 7.5
CVE-2025-41335
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via id and id_sociedad Parameters
CVSS 7.5
CVE-2025-41114
HIGH
canaldenuncia.app < 4.4.8 - Unauthenticated Information Disclosure via id_denuncia and id_user Parameters
CVSS 7.5
CVE-2025-41113
HIGH
canaldenuncia.app < 4.4.8 - Unauthenticated Information Disclosure via id_denuncia Parameter
CVSS 7.5
CVE-2025-41112
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via web Parameter
CVSS 7.5
CVE-2025-41111
HIGH
canaldenuncia.app < 4.4.8 - Missing Authorization via id_denuncia Parameter
CVSS 7.5
CVE-2025-12389
MEDIUM
Import Export For WooCommerce <1.6.2 - Info Disclosure
CVSS 4.3
CVE-2025-12350
MEDIUM
DominoKit <= 1.1.0 - Unauthenticated Arbitrary Plugin Settings Update via wp_ajax_nopriv_dominokit_option_admin_action
CVSS 5.3
CVE-2025-12158
CRITICAL
Simple User Capabilities plugin - Privilege Escalation
CVSS 9.8
CVE-2025-12157
MEDIUM
Simple User Capabilities <1.0 - Info Disclosure
CVSS 5.3
CVE-2025-12156
MEDIUM
WordPress All in One plugin <2.2.6 - Info Disclosure
CVSS 4.3
CVE-2025-11890
HIGH
Crypto Payment Gateway with Payeer for WooCommerce <1.0.3 - Auth By...
CVSS 7.5
CVE-2025-11758
MEDIUM
All in One Time Clock Lite <2.0.3 - Auth Bypass
CVSS 6.5
CVE-2025-10896
HIGH
WordPress <1.0.2.3 - Unrestricted Upload of File with Dangerous Type
CVSS 8.8
CVE-2025-63293
MEDIUM
FairSketch Rise Ultimate Project Manager & CRM 3.9.4 - Authenticated Missing Authorization in Ticketing API
CVSS 6.5
CVE-2025-64294
MEDIUM
WP Snow Effect <= 1.1.19 - Missing Authorization to Notice Dismissal Functionality
CVSS 5.3
CVE-2025-36367
HIGH
IBM i 7.2-7.6 - Missing Authorization Leading to Privilege Escalation
CVSS 8.8
CVE-2025-12180
MEDIUM
Qi Blocks plugin <1.4.3 - Auth Bypass
CVSS 4.3
Details
Vulnerabilities
8,324
Exploit Likelihood
High