CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,064 vulnerabilities with CWE-863
CVE-2025-49810 LOW
Mattermost 10.5.0-10.5.8 - Incorrect Authorization in AI Posts Thread Access
CVSS 3.5
CVE-2025-27213 MEDIUM
UniFi Connect <1.5.18-1.9.324 - Info Disclosure
CVSS 4.9
CVE-2025-57728 MEDIUM
JetBrains IntelliJ IDEA < 2025.2 - Unauthenticated Hidden File Discovery via Code With Me Guest Access
CVSS 6.5
CVE-2025-9228 MEDIUM
MiR Robots < 3.0.0 - Incorrect Authorization in Note Creation
CVSS 4.3
CVE-2025-55213 CRITICAL
OpenFGA <1.9.5 - Improper Policy Enforcement
CVSS 9.8
CVE-2025-55205 CRITICAL
Capsule <0.10.3 - Privilege Escalation
CVSS 9.0
CVE-2025-36120 HIGH
IBM Storage Virtualize 8.4-8.7 - Authenticated Privilege Escalation via SSH Session
CVSS 8.8
CVE-2025-7773 HIGH
5032 16pt Digital Configurable - Info Disclosure
CVE-2025-49556 HIGH
Adobe Commerce < 2.4.4 - Incorrect Authorization
CVSS 7.5
CVE-2025-42951 HIGH
SAP Business One - Privilege Escalation
CVSS 8.8
CVE-2025-8807 MEDIUM
tianti < 2.3 - Missing Authorization in User Save Endpoint
CVSS 6.3
CVE-2025-8796 MEDIUM
LitmusChaos Litmus < 3.19.0 - Missing Authorization in Delete Request Handler
CVSS 5.4
CVE-2025-54888 HIGH
Fedify < 1.3.20 - Incorrect Authorization
CVE-2025-55077 HIGH
Tyler Technologies ERP Pro 9 SaaS - Command Injection
CVSS 7.4
CVE-2025-8533 MEDIUM
Fantastical <4.0.15 - Privilege Escalation
CVE-2025-20332 MEDIUM
Cisco Identity Services Engine Software - Authenticated Incorrect Authorization via Crafted HTTP Request
CVSS 4.3
CVE-2025-54253 CRITICAL KEV
Adobe Experience Manager Forms < 6.5.23.0 - Unauthenticated Arbitrary Code Execution via Misconfiguration
CVSS 10.0
CVE-2025-54554 MEDIUM
Tera Insights tiCrypt <2025-07-17 - Info Disclosure
CVSS 5.3
CVE-2025-20701 HIGH
Airoha Bluetooth audio SDK - Privilege Escalation
CVSS 8.8
CVE-2025-8435 HIGH
Online Movie Streaming 1.0 - Missing Authorization in /admin-control.php ID Parameter
CVSS 7.3
CVE-2025-8434 HIGH
Online Movie Streaming 1.0 - Missing Authorization in /admin.php ID Parameter
CVSS 7.3
CVE-2025-8068 MEDIUM
HT Mega < 2.9.1 - Authenticated Arbitrary Data Deletion via Improper Capability Check
CVSS 4.3
CVE-2025-54583 MEDIUM
finos/gitproxy < 1.19.2 - Incorrect Authorization via Policy Bypass
CVSS 6.5
CVE-2025-43251 MEDIUM
macOS Sequoia <15.6 - Privilege Escalation
CVSS 5.5
CVE-2025-43230 MEDIUM
iPadOS < 17.7.9 - Incorrect Authorization
CVSS 4.0
Details
Vulnerabilities 3,064
Exploit Likelihood High