The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,063 vulnerabilities with CWE-863
CVE-2025-12149
MEDIUM
Search Guard FLX <3.1.2 - Info Disclosure
CVE-2025-41436
LOW
Mattermost < 11.0 - Unauthenticated Archived Channel Access via Open in Channel Functionality
CVSS 3.1
CVE-2025-11776
MEDIUM
Mattermost < 11.0.0 - Unauthenticated Archived Channel Discovery via Search API
CVSS 4.3
CVE-2025-64753
MEDIUM
grist-core < 1.7.7 - Incorrect Authorization via Compare Endpoint
CVSS 5.3
CVE-2025-64746
MEDIUM
Directus < 11.13.0 - Improper Access Control via Stale Field Permission References
CVSS 4.6
CVE-2025-11777
LOW
Mattermost 10.5.0-10.5.11 and 10.11.0-10.11.3 - Incorrect Authorization via Add Channel Member API
CVSS 3.1
CVE-2025-64707
MEDIUM
Frappe Learning 2.0.0-2.40.9 - Incorrect Authorization via Role Cache
CVSS 5.4
CVE-2025-13063
HIGH
DinukaNavaratna Dee Store 1.0 - Auth Bypass
CVSS 7.3
CVE-2025-65002
HIGH
Fujitsu/Fsas Technologies iRMC S6 <1.37S - Info Disclosure
CVSS 7.5
CVE-2025-61830
HIGH
Adobe Pass < 3.7.3 - Incorrect Authorization
CVSS 7.1
CVE-2025-11862
HIGH
Verve Asset Manager - Info Disclosure
CVE-2025-49145
HIGH
Combodo iTop < 2.7.13 - Authenticated Database Deletion via Webhook Callback
CVSS 8.7
CVE-2025-12925
HIGH
rymcu forest < 2025-09-04 - Missing Authorization in UserDicController
CVSS 7.3
CVE-2025-12924
MEDIUM
rymcu forest < 2025-09-07 - Missing Authorization in BankController GlobalResult
CVSS 4.3
CVE-2025-12621
MEDIUM
WooCommerce Flexible Refund <1.0.42 - Info Disclosure
CVSS 5.3
CVE-2025-64490
HIGH
SuiteCRM < 7.14.8 - Incorrect Authorization in Resource Calendar and Project Screens
CVSS 8.3
CVE-2025-37736
HIGH
Elastic Cloud Enterprise - Privilege Escalation
CVSS 8.8
CVE-2025-63687
MEDIUM
RyMCU Forest - Privilege Escalation
CVSS 6.5
CVE-2025-43459
MEDIUM
Apple Watch <26.1 - Info Disclosure
CVSS 4.6
CVE-2025-43397
MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Denial of Service via Permissions Issue
CVSS 5.5
CVE-2025-43387
HIGH
macOS <15.7.2 & <26.1 - Privilege Escalation
CVSS 7.8
CVE-2025-43336
MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Unprotected User Data Exposure via Permissions Issue
CVSS 4.4
CVE-2025-12038
MEDIUM
Folderly <= 0.3 - Authenticated Data Modification via REST API Endpoint
CVSS 4.3
CVE-2025-62275
MEDIUM
Liferay DXP 7.4.0-7.4.3.111 & 2023.Q4.0-2023.Q4.10 - Unauthenticated Image Access
CVSS 5.3
CVE-2025-34273
MEDIUM
Nagios Log Server < 2024R2.0.3 - Incorrect Authorization for Global Dashboard Deletion
CVSS 6.5
Details
Vulnerabilities
3,063
Exploit Likelihood
High