CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,063 vulnerabilities with CWE-863
CVE-2025-12149 MEDIUM
Search Guard FLX <3.1.2 - Info Disclosure
CVE-2025-41436 LOW
Mattermost < 11.0 - Unauthenticated Archived Channel Access via Open in Channel Functionality
CVSS 3.1
CVE-2025-11776 MEDIUM
Mattermost < 11.0.0 - Unauthenticated Archived Channel Discovery via Search API
CVSS 4.3
CVE-2025-64753 MEDIUM
grist-core < 1.7.7 - Incorrect Authorization via Compare Endpoint
CVSS 5.3
CVE-2025-64746 MEDIUM
Directus < 11.13.0 - Improper Access Control via Stale Field Permission References
CVSS 4.6
CVE-2025-11777 LOW
Mattermost 10.5.0-10.5.11 and 10.11.0-10.11.3 - Incorrect Authorization via Add Channel Member API
CVSS 3.1
CVE-2025-64707 MEDIUM
Frappe Learning 2.0.0-2.40.9 - Incorrect Authorization via Role Cache
CVSS 5.4
CVE-2025-13063 HIGH
DinukaNavaratna Dee Store 1.0 - Auth Bypass
CVSS 7.3
CVE-2025-65002 HIGH
Fujitsu/Fsas Technologies iRMC S6 <1.37S - Info Disclosure
CVSS 7.5
CVE-2025-61830 HIGH
Adobe Pass < 3.7.3 - Incorrect Authorization
CVSS 7.1
CVE-2025-11862 HIGH
Verve Asset Manager - Info Disclosure
CVE-2025-49145 HIGH
Combodo iTop < 2.7.13 - Authenticated Database Deletion via Webhook Callback
CVSS 8.7
CVE-2025-12925 HIGH
rymcu forest < 2025-09-04 - Missing Authorization in UserDicController
CVSS 7.3
CVE-2025-12924 MEDIUM
rymcu forest < 2025-09-07 - Missing Authorization in BankController GlobalResult
CVSS 4.3
CVE-2025-12621 MEDIUM
WooCommerce Flexible Refund <1.0.42 - Info Disclosure
CVSS 5.3
CVE-2025-64490 HIGH
SuiteCRM < 7.14.8 - Incorrect Authorization in Resource Calendar and Project Screens
CVSS 8.3
CVE-2025-37736 HIGH
Elastic Cloud Enterprise - Privilege Escalation
CVSS 8.8
CVE-2025-63687 MEDIUM
RyMCU Forest - Privilege Escalation
CVSS 6.5
CVE-2025-43459 MEDIUM
Apple Watch <26.1 - Info Disclosure
CVSS 4.6
CVE-2025-43397 MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Denial of Service via Permissions Issue
CVSS 5.5
CVE-2025-43387 HIGH
macOS <15.7.2 & <26.1 - Privilege Escalation
CVSS 7.8
CVE-2025-43336 MEDIUM
macOS < 14.8.2, < 15.7.2, < 26.1 - Unprotected User Data Exposure via Permissions Issue
CVSS 4.4
CVE-2025-12038 MEDIUM
Folderly <= 0.3 - Authenticated Data Modification via REST API Endpoint
CVSS 4.3
CVE-2025-62275 MEDIUM
Liferay DXP 7.4.0-7.4.3.111 & 2023.Q4.0-2023.Q4.10 - Unauthenticated Image Access
CVSS 5.3
CVE-2025-34273 MEDIUM
Nagios Log Server < 2024R2.0.3 - Incorrect Authorization for Global Dashboard Deletion
CVSS 6.5
Details
Vulnerabilities 3,063
Exploit Likelihood High