The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,064 vulnerabilities with CWE-863
CVE-2025-49825
CRITICAL
Teleport <= 17.5.1 - Unauthenticated Remote Authentication Bypass
CVSS 9.8
CVE-2025-3880
MEDIUM
Opinion Stage Poll, Survey & Quiz Maker <= 19.9.0 - Authenticated Data Modification via Capability Check
CVSS 4.3
CVE-2025-49586
HIGH
XWiki 7.3-16.4.6 - Authenticated Remote Code Execution via App Within Minutes Application Edit
CVSS 8.8
CVE-2025-6003
MEDIUM
WordPress SSO <*.5.3 - Info Disclosure
CVSS 5.3
CVE-2025-48446
HIGH
Drupal Commerce Alphabank Redirect <1.0.3 - Auth Bypass
CVSS 8.8
CVE-2025-48445
HIGH
Drupal Commerce Eurobank (Redirect) <2.1.1 - Functionality Misuse
CVSS 8.8
CVE-2025-4128
LOW
Mattermost 9.11.0-9.11.13 and 10.5.0-10.5.4 - Incorrect Authorization via Teams API
CVSS 3.1
CVE-2025-36578
MEDIUM
Dell Wyse Management Suite < 5.2 - Incorrect Authorization
CVSS 6.8
CVE-2025-40568
MEDIUM
RUGGEDCOM RST2428P - Path Traversal
CVSS 4.3
CVE-2025-40567
MEDIUM
RUGGEDCOM RST2428P - Path Traversal
CVSS 6.5
CVE-2025-40670
HIGH
TCMAN GIM v11 - Unauthenticated Incorrect Authorization via /PC/frmGestionUser.aspx/updateUser
CVSS 8.8
CVE-2025-40669
MEDIUM
TCMAN GIM v11 - Unauthenticated Incorrect Authorization via POST Request to /PC/Options.aspx
CVSS 6.5
CVE-2025-40668
MEDIUM
TCMAN GIM v11 - Incorrect Authorization via Password Change Endpoint
CVSS 6.5
CVE-2025-49599
MEDIUM
Huawei EG8141A5 <V5R019C00S100 - Privilege Escalation
CVSS 4.1
CVE-2025-48935
CRITICAL
Deno 2.2.0-2.2.5 - Incorrect Authorization via ATTACH DATABASE Statement
CVSS 9.1
CVE-2025-48888
MEDIUM
Deno <2.1.13, <2.2.13, <2.3.2 - Info Disclosure
CVSS 5.3
CVE-2025-21479
HIGH
KEV
Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via Unauthorized GPU Micronode Command Execution
CVSS 8.6
CVE-2025-21480
HIGH
KEV
Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via Unauthorized GPU Micronode Command Execution
CVSS 8.6
CVE-2025-3260
HIGH
Grafana API <v2alpha1 - Auth Bypass
CVSS 8.3
CVE-2025-20674
CRITICAL
OpenWrt - Unauthenticated Arbitrary Packet Injection via Missing Permission Check
CVSS 9.8
CVE-2025-48948
MEDIUM
navidrome < 0.56.0 - Authenticated Incorrect Authorization via Transcoding Configuration
CVSS 6.5
CVE-2025-3611
LOW
Mattermost 9.11.0-9.11.12 10.5.0-10.5.3 10.7.0 - Authenticated Incorrect Authorization via Team API Endpoint
CVSS 3.1
CVE-2025-1792
LOW
Mattermost <10.7.0, <10.5.3, <9.11.12 - Info Disclosure
CVSS 3.1
CVE-2025-48881
HIGH
Valtimo <12.12.0.RELEASE - Info Disclosure
CVSS 8.3
CVE-2025-48757
CRITICAL
Lovable <2025-04-15 - Info Disclosure
CVSS 9.3
Details
Vulnerabilities
3,064
Exploit Likelihood
High