The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,064 vulnerabilities with CWE-863
CVE-2025-6168
LOW
GitLab 18.0.0-18.0.3 - Authenticated Group Invitation Restriction Bypass via Crafted API Requests
CVSS 2.7
CVE-2025-4972
LOW
GitLab 18.0.0-18.0.3 - Authenticated Invitation Restriction Bypass via Group Invitation Manipulation
CVSS 2.7
CVE-2025-3396
MEDIUM
GitLab EE <17.11.6, <18.0.4, <18.1.2 - Auth Bypass
CVSS 4.3
CVE-2025-49536
HIGH
ColdFusion <= 2025.2, 2023.14, 2021.20 - Incorrect Authorization
CVSS 7.3
CVE-2025-21450
CRITICAL
Qualcomm AR8035 and FastConnect Firmware - Cryptographic Issue via Insecure Download Connection
CVSS 9.1
CVE-2025-20999
MEDIUM
Samsung Android - Incorrect Authorization in Wi-Fi Password Access
CVSS 4.1
CVE-2025-20300
MEDIUM
Splunk Enterprise <9.4.2, 9.3.5, 9.2.6, 9.1.9 - Info Disclosure
CVSS 4.3
CVE-2025-26850
CRITICAL
Quest KACE SMA <14.0.97, <14.1.19 - Privilege Escalation
CVSS 9.3
CVE-2025-0885
LOW
OpenText GroupWise 7-17.5,23.4,24.1-24.4 - Auth Bypass
CVE-2025-32462
LOW
sudo < 1.9.17p1 - Incorrect Authorization via Host Specification Bypass
CVSS 2.8
CVE-2025-47871
MEDIUM
Mattermost 9.11.0-9.11.15 10.5.0-10.5.5 10.6.0-10.6.5 10.7.0-10.7.2 10.8.0 - Authenticated Information Disclosure
CVSS 4.3
CVE-2025-46702
MEDIUM
Mattermost <10.5.5-10.8.0 - Privilege Escalation
CVSS 5.4
CVE-2025-53391
CRITICAL
Debian zuluPolkit/CMakeLists.txt - Privilege Escalation
CVSS 9.3
CVE-2025-6702
MEDIUM
linlinjava litemall 1.8.0 - Incorrect Privilege Assignment via wx/comment/post adminComment Parameter
CVSS 4.3
CVE-2025-6707
MEDIUM
MongoDB 5.0.0-5.0.30 - Authenticated Privilege Escalation via Stale Privilege Execution
CVSS 4.2
CVE-2025-5822
HIGH
Autel MaxiCharger AC Wallbox - Privilege Escalation
CVSS 8.8
CVE-2025-49550
MEDIUM
Adobe Commerce - Incorrect Authorization leading to Security Feature Bypass
CVSS 4.3
CVE-2025-49549
LOW
Adobe Commerce <= 2.4.8 - Incorrect Authorization
CVSS 2.7
CVE-2025-52890
HIGH
Incus 6.12-6.13 - Incorrect Authorization via ACL Bypass in Bridge Device Rules
CVSS 8.1
CVE-2025-48466
HIGH
Advantech WISE-4000 LAN Modbus TCP - Unauthenticated Digital Output Manipulation
CVSS 8.1
CVE-2025-52918
MEDIUM
Yealink RPS < 2025-05-26 - Incorrect Authorization via OpenAPI Access
CVSS 5.0
CVE-2025-52487
HIGH
Dnnsoftware Dotnetnuke < 10.0.1 - Incorrect Authorization
CVSS 7.5
CVE-2025-3228
MEDIUM
Mattermost <10.5.5-10.8.0 - Info Disclosure
CVSS 4.3
CVE-2025-3227
MEDIUM
Mattermost <10.5.5-10.8.0 - Privilege Escalation
CVSS 4.3
CVE-2025-5071
HIGH
WordPress AI Engine <2.8.3 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities
3,064
Exploit Likelihood
High