The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,064 vulnerabilities with CWE-863
CVE-2025-43197
MEDIUM
macOS < 13.7.7, < 14.7.7, < 15.6 - Unprotected User Data Exposure via Missing Entitlement Checks
CVSS 4.0
CVE-2025-53902
MEDIUM
Tuleap <16.9.99.1752585665, <16.8-6, <16.9-5 - Info Disclosure
CVSS 4.3
CVE-2025-54533
MEDIUM
JetBrains TeamCity < 2025.07 - Unauthenticated Build Settings Disclosure via VCS Configuration
CVSS 4.3
CVE-2025-54532
MEDIUM
JetBrains TeamCity < 2025.07 - Unauthenticated Build Settings Disclosure via Snapshot Dependencies
CVSS 4.3
CVE-2025-54569
MEDIUM
Malwarebytes Binisoft Windows Firewall Control <6.16.0.0 - Privileg...
CVSS 4.5
CVE-2025-54596
MEDIUM
Abnormal Security /v1.0/rbac/users_v2/ - Privilege Escalation
CVSS 4.3
CVE-2025-0765
MEDIUM
GitLab CE/EE <18.0.5-18.2.1 - Info Disclosure
CVSS 4.3
CVE-2025-6018
HIGH
pam-config - Local Privilege Escalation via Polkit Bypass
CVSS 7.8
CVE-2025-29757
CRITICAL
Growatt Cloud - Privilege Escalation
CVE-2025-53943
HIGH
VoidBot Open-Source <1.0.0 - Privilege Escalation
CVE-2025-6981
MEDIUM
GitHub Enterprise Server < 3.14.5 - Unauthorized Internal Repository Read Access via Contractors API
CVSS 4.3
CVE-2025-50086
MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in Server Components Services
CVSS 4.9
CVE-2025-50085
MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - DoS and Data Manipulation in InnoDB
CVSS 5.5
CVE-2025-50084
MEDIUM
MySQL 8.0.0-8.0.42, 8.4.0-8.4.5, 9.0.0-9.3.0 - Authenticated Denial of Service in Server Optimizer
CVSS 4.9
CVE-2025-30751
HIGH
Oracle Database Server 19.27 and 23.4-23.8 - Authenticated Database Takeover via Oracle Net
CVSS 8.8
CVE-2025-30750
LOW
Oracle Database Server 19.3-19.27, 21.3-21.18, 23.4-23.8 - Authenticated Unauthorized Data Manipulation in Unified Audit
CVSS 2.4
CVE-2025-30748
MEDIUM
Oracle PeopleSoft Enterprise PeopleTools 8.60-8.62 - Unauthenticated Incorrect Authorization via PIA Core Technology
CVSS 6.1
CVE-2025-30747
MEDIUM
Oracle PeopleSoft Enterprise PeopleTools 8.60-8.62 - Unauthenticated Unauthorized Data Access via PIA Core Technology
CVSS 4.3
CVE-2025-30744
HIGH
Oracle Mobile Field Service 12.2.3-12.2.13 - Incorrect Authorization via Multiplatform Sync Errors
CVSS 8.1
CVE-2025-30743
HIGH
Oracle Lease and Finance Management 12.2.13 - Unauthorized Data Access and Modification via Internal Operations
CVSS 8.1
CVE-2025-30739
MEDIUM
Oracle CRM Technical Foundation 12.2.11-12.2.13 - Authenticated Incorrect Authorization in Preferences
CVSS 5.5
CVE-2025-53895
HIGH
ZITADEL <4.0.0-rc.2, 3.3.2, 2.71.13, 2.70.14 - Privilege Escalation
CVSS 8.8
CVE-2025-53836
CRITICAL
XWiki Rendering <13.10.11-14.4.7-14.10 - RCE
CVSS 9.9
CVE-2025-5199
HIGH
Canonical Multipass <= 1.15.1 - Privilege Escalation via Launch Daemon File Modification
CVSS 7.3
CVE-2025-6549
MEDIUM
Juniper Networks Junos OS - Auth Bypass
CVSS 6.5
Details
Vulnerabilities
3,064
Exploit Likelihood
High