The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,064 vulnerabilities with CWE-863
CVE-2025-43561
CRITICAL
ColdFusion 2025.1 2023.13 2021.19 and earlier - Authenticated Remote Code Execution via Authorization Bypass
CVSS 9.1
CVE-2025-4646
HIGH
Centreon web <24.04.10-24.10.4 - Privilege Escalation
CVSS 7.2
CVE-2025-27696
HIGH
Apache Superset <= 4.1.1 - Authenticated Ownership Takeover via Dashboard Chart or Dataset
CVSS 8.8
CVE-2025-31227
MEDIUM
iPadOS < 18.5 - Unauthorized Access to Deleted Call Recordings
CVSS 4.6
CVE-2025-30440
MEDIUM
macOS < 13.7.6, < 14.7.6, < 15.5 - ASLR Bypass via Incorrect Authorization
CVSS 5.5
CVE-2025-46744
LOW
SEL Blueframe OS < 1.12.0 - Authenticated User Account Metadata Tampering
CVSS 2.7
CVE-2025-29827
CRITICAL
Azure Automation - Privilege Escalation via Improper Authorization
CVSS 9.9
CVE-2025-26842
HIGH
Znuny < 7.1.3 - Incorrect Authorization in CommunicationLog
CVSS 7.5
CVE-2025-46265
HIGH
F5OS-A and F5OS-C >=1.6.0 <1.6.2 - Authenticated Incorrect Authorization
CVSS 8.8
CVE-2025-36546
HIGH
F5OS-A 1.5.1-1.5.3 and F5OS-C 1.6.0-1.6.2 - Incorrect Authorization via SSH Key-Based Authentication
CVSS 8.1
CVE-2025-3476
CRITICAL
OpenText Operations Bridge Manager - Privilege Escalation
CVE-2025-3272
MEDIUM
OpenText Operations Bridge Manager <24.4 - Auth Bypass
CVE-2025-3609
MEDIUM
Reales WP STPT <2.1.2 - Privilege Escalation
CVSS 5.3
CVE-2025-3879
MEDIUM
HashiCorp Vault - Incorrect Authorization via Azure Auth Method Bound Location Bypass
CVSS 6.6
CVE-2025-46569
HIGH
Open Policy Agent < 1.4.0 - Rego Injection via HTTP Data API Path
CVE-2025-23244
HIGH
NVIDIA GPU Display Driver - Privilege Escalation
CVSS 7.8
CVE-2025-32971
LOW
XWiki 4.5.1-15.10.12, 16.0.0-rc-1-16.4.3, 16.5.0-rc-1-16.8.0-rc-1 - Incorrect Authorization in Solr Script Service
CVSS 3.8
CVE-2025-40619
HIGH
Bookgy - Unauthenticated Incorrect Authorization
CVSS 7.5
CVE-2025-3963
HIGH
withstars Books-Management-System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-3960
HIGH
withstars Books-Management-System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-3647
MEDIUM
Moodle < 4.1.18 - Incorrect Authorization in Cohort Data Access
CVSS 4.3
CVE-2025-3645
MEDIUM
Moodle < 4.1.18 - Incorrect Authorization in Messaging Web Service
CVSS 4.3
CVE-2025-3644
MEDIUM
Moodle < 4.1.18 - Incorrect Authorization in Course Section Deletion
CVSS 4.3
CVE-2025-3861
MEDIUM
Prevent Direct Access - Protect WordPress Files <2.8.8.2 - Privileg...
CVSS 5.4
CVE-2025-46544
MEDIUM
Sherpa Orchestrator 141851 - Privilege Escalation
CVSS 6.4
Details
Vulnerabilities
3,064
Exploit Likelihood
High