The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,064 vulnerabilities with CWE-863
CVE-2025-49810
LOW
Mattermost 10.5.0-10.5.8 - Incorrect Authorization in AI Posts Thread Access
CVSS 3.5
CVE-2025-27213
MEDIUM
UniFi Connect <1.5.18-1.9.324 - Info Disclosure
CVSS 4.9
CVE-2025-57728
MEDIUM
JetBrains IntelliJ IDEA < 2025.2 - Unauthenticated Hidden File Discovery via Code With Me Guest Access
CVSS 6.5
CVE-2025-9228
MEDIUM
MiR Robots < 3.0.0 - Incorrect Authorization in Note Creation
CVSS 4.3
CVE-2025-55213
CRITICAL
OpenFGA <1.9.5 - Improper Policy Enforcement
CVSS 9.8
CVE-2025-55205
CRITICAL
Capsule <0.10.3 - Privilege Escalation
CVSS 9.0
CVE-2025-36120
HIGH
IBM Storage Virtualize 8.4-8.7 - Authenticated Privilege Escalation via SSH Session
CVSS 8.8
CVE-2025-7773
HIGH
5032 16pt Digital Configurable - Info Disclosure
CVE-2025-49556
HIGH
Adobe Commerce < 2.4.4 - Incorrect Authorization
CVSS 7.5
CVE-2025-42951
HIGH
SAP Business One - Privilege Escalation
CVSS 8.8
CVE-2025-8807
MEDIUM
tianti < 2.3 - Missing Authorization in User Save Endpoint
CVSS 6.3
CVE-2025-8796
MEDIUM
LitmusChaos Litmus < 3.19.0 - Missing Authorization in Delete Request Handler
CVSS 5.4
CVE-2025-54888
HIGH
Fedify < 1.3.20 - Incorrect Authorization
CVE-2025-55077
HIGH
Tyler Technologies ERP Pro 9 SaaS - Command Injection
CVSS 7.4
CVE-2025-8533
MEDIUM
Fantastical <4.0.15 - Privilege Escalation
CVE-2025-20332
MEDIUM
Cisco Identity Services Engine Software - Authenticated Incorrect Authorization via Crafted HTTP Request
CVSS 4.3
CVE-2025-54253
CRITICAL
KEV
Adobe Experience Manager Forms < 6.5.23.0 - Unauthenticated Arbitrary Code Execution via Misconfiguration
CVSS 10.0
CVE-2025-54554
MEDIUM
Tera Insights tiCrypt <2025-07-17 - Info Disclosure
CVSS 5.3
CVE-2025-20701
HIGH
Airoha Bluetooth audio SDK - Privilege Escalation
CVSS 8.8
CVE-2025-8435
HIGH
Online Movie Streaming 1.0 - Missing Authorization in /admin-control.php ID Parameter
CVSS 7.3
CVE-2025-8434
HIGH
Online Movie Streaming 1.0 - Missing Authorization in /admin.php ID Parameter
CVSS 7.3
CVE-2025-8068
MEDIUM
HT Mega < 2.9.1 - Authenticated Arbitrary Data Deletion via Improper Capability Check
CVSS 4.3
CVE-2025-54583
MEDIUM
finos/gitproxy < 1.19.2 - Incorrect Authorization via Policy Bypass
CVSS 6.5
CVE-2025-43251
MEDIUM
macOS Sequoia <15.6 - Privilege Escalation
CVSS 5.5
CVE-2025-43230
MEDIUM
iPadOS < 17.7.9 - Incorrect Authorization
CVSS 4.0
Details
Vulnerabilities
3,064
Exploit Likelihood
High