The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,063 vulnerabilities with CWE-863
CVE-2025-65900
MEDIUM
Kalmia CMS <0.2.0 - Info Disclosure
CVSS 6.5
CVE-2025-14016
MEDIUM
macrozheng mall-swarm < 1.0.3 - Improper Authorization via /member/readHistory/delete ids Parameter
CVSS 5.4
CVE-2025-66406
MEDIUM
Step CA <0.29.0 - Improper Authorization
CVSS 5.0
CVE-2025-20381
MEDIUM
Splunk MCP Server app <0.2.4 - Auth Bypass
CVSS 5.4
CVE-2025-12756
MEDIUM
Mattermost <11.0.2-10.12.1-10.11.4-10.5.12 - Privilege Escalation
CVSS 4.3
CVE-2025-13653
MEDIUM
Search Guard FLX <4.0.0 - Info Disclosure
CVSS 4.3
CVE-2025-13829
HIGH
Data Illusion Zumbrunn NGSurvey - Info Disclosure
CVE-2025-13813
MEDIUM
mogublog < 5.2 - Missing Authorization in Storage Management Endpoint
CVSS 5.6
CVE-2025-13806
HIGH
nutzam NutzBoot < 2.6.0 - Improper Authorization in Transaction API
CVSS 7.3
CVE-2025-66433
MEDIUM
HTCondor Access Point <25.3.1 - Privilege Escalation
CVSS 4.2
CVE-2025-66424
MEDIUM
Tryton trytond <7.6.11 - Info Disclosure
CVSS 6.5
CVE-2025-66423
HIGH
Tryton trytond <6.0-7.6.11 - Info Disclosure
CVSS 7.1
CVE-2025-66360
HIGH
Logpoint <7.7.0 - Privilege Escalation
CVSS 8.8
CVE-2025-12971
MEDIUM
Folders - Unlimited Folders to Organize Media Library Folder, Pages...
CVSS 4.3
CVE-2025-55469
CRITICAL
youlai-boot <2.21.1 - Privilege Escalation
CVSS 9.8
CVE-2025-9803
HIGH
lunary 1.9.34 - Account Takeover via Improper Google OAuth Audience Validation
CVSS 8.8
CVE-2025-13432
MEDIUM
Terraform 1.0.0-1.0.3 - Incorrect Authorization in State Version Creation
CVSS 4.3
CVE-2025-62189
MEDIUM
LogStare Collector < 2.4.2 - Incorrect Authorization in UserRegistration
CVSS 4.3
CVE-2025-62730
HIGH
soplanning < 1.55.00 - Authenticated Privilege Escalation via User Management Tab
CVSS 8.8
CVE-2025-13468
MEDIUM
SourceCodester Alumni Management System 1.0 - Missing Authorization in Delete Handler
CVSS 5.4
CVE-2025-59111
MEDIUM
Windu CMS 4.1 - Broken Access Control in User Editing Functionality
CVSS 6.5
CVE-2025-41346
CRITICAL
WinPlus 24.11.27 - Incorrect Authorization via Numerical ID Impersonation
CVSS 9.8
CVE-2025-65073
HIGH
OpenStack Keystone < 26.0.1, 27.0.0, 28.0.0 - Incorrect Authorization via AWS Signature
CVSS 7.5
CVE-2025-7736
LOW
GitLab CE/EE <18.3.6-18.5.2 - Auth Bypass
CVSS 3.1
CVE-2025-11865
MEDIUM
GitLab 18.1-18.3.6, 18.4-18.4.4, 18.5-18.5.2 - Incorrect Authorization
CVSS 4.3
Details
Vulnerabilities
3,063
Exploit Likelihood
High