The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,064 vulnerabilities with CWE-863
CVE-2025-8886
MEDIUM
Usta Information Systems Inc. Aybs Interaktif - Privilege Escalation
CVSS 6.7
CVE-2025-7374
MEDIUM
WP JobHunt <= 7.6 - Authenticated Authorization Bypass via Inactive Account Login
CVSS 5.4
CVE-2025-11340
HIGH
GitLab EE <18.3.4-18.4.2 - Privilege Escalation
CVSS 7.7
CVE-2025-11439
MEDIUM
JhumanJ OpnForm <1.9.3 - Auth Bypass
CVSS 4.3
CVE-2025-11438
MEDIUM
JhumanJ OpnForm <1.9.3 - Auth Bypass
CVSS 6.3
CVE-2025-44824
HIGH
Nagios Log Server < 2024R1.3.2 - Authenticated Denial of Service via Elasticsearch Stop API
CVSS 8.5
CVE-2025-3719
HIGH
Nozomi Networks CMC and Guardian < 25.2.0 - Authenticated Privilege Escalation via CLI Command Execution
CVSS 8.1
CVE-2025-59451
LOW
YoSmart YoLink <2025-10-02 - Info Disclosure
CVSS 3.5
CVE-2025-59449
MEDIUM
YoSmart YoLink MQTT broker <2025-10-02 - SSRF
CVSS 4.9
CVE-2025-10696
MEDIUM
OpenSupports 4.11.0 - Incorrect Authorization via Supervised Users Endpoint
CVSS 5.4
CVE-2025-49641
MEDIUM
Zabbix 6.0.0-6.0.40 - Incorrect Authorization via problem.view.refresh Action
CVSS 4.3
CVE-2025-27236
MEDIUM
Zabbix 6.0.38-6.0.41 - Incorrect Authorization via User Search API
CVSS 6.5
CVE-2025-11239
MEDIUM
KNIME Business Hub <1.16.0 - Info Disclosure
CVSS 4.3
CVE-2025-41246
HIGH
VMware Tools for Windows - Privilege Escalation
CVSS 7.6
CVE-2025-11060
MEDIUM
SurrealDB 2.3.0-2.3.7 - Incorrect Authorization via LIVE SELECT Subscription
CVSS 5.7
CVE-2025-59824
MEDIUM
Omni < 0.48.0 - Incorrect Authorization via WireGuard SideroLink
CVSS 5.4
CVE-2025-43806
MEDIUM
Liferay Digital Experience Platform 2023.Q3.1-2023.Q3.10 - Authenticated Incorrect Authorization in Batch Engine
CVSS 4.3
CVE-2025-59420
HIGH
Authlib < 1.6.4 - Insufficient Verification of Data Authenticity via Critical Header Parameter Bypass
CVSS 7.5
CVE-2025-59714
MEDIUM
Internet2 Grouper 5.17.1-5.20.5 - Incorrect Authorization in Loader Job Configuration
CVSS 6.5
CVE-2025-10016
HIGH
Sparkle framework - Privilege Escalation
CVE-2025-10015
MEDIUM
Sparkle < 2.7.2 - Unauthenticated Incorrect Authorization via XPC Service Registration
CVE-2025-43307
MEDIUM
macOS < 26 - Unauthorized Sensitive User Data Access
CVSS 4.0
CVE-2025-31254
MEDIUM
Safari < 26.0 - Unexpected URL Redirection via Malicious Web Content
CVSS 5.4
CVE-2025-59376
LOW
feisky mcp-kubernetes-server < 0.1.11 - Command Injection via Chained Command Bypass
CVSS 3.7
CVE-2025-43789
MEDIUM
Liferay DXP 2024.Q1.1-2024.Q1.9 & 7.4.0-7.4.3.119 - Incorrect Authorization in JSON WS
CVSS 5.3
Details
Vulnerabilities
3,064
Exploit Likelihood
High