The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,064 vulnerabilities with CWE-863
CVE-2025-24409
HIGH
Adobe Commerce < 2.4.4 - Incorrect Authorization
CVSS 8.2
CVE-2025-24407
HIGH
Adobe Commerce < 2.4.8-beta1 - Incorrect Authorization
CVSS 7.1
CVE-2025-24872
MEDIUM
SAP ABAP Platform - Privilege Escalation
CVSS 4.3
CVE-2025-24869
MEDIUM
SAP NetWeaver Application Server Java - Info Disclosure
CVSS 4.3
CVE-2025-24200
MEDIUM
KEV
iPadOS < 15.8.4, < 16.7.11, < 17.7.5, < 18.3.1 - Authorization Bypass via USB Restricted Mode
CVSS 6.1
CVE-2025-23419
MEDIUM
F5 NGINX 1.11.4-1.26.2 and NGINX Plus R28-R31 - Incorrect Authorization via TLS Session Resumption
CVSS 4.3
CVE-2025-24860
MEDIUM
Apache Cassandra <4.0.15, <4.1.7 - Auth Bypass
CVSS 5.4
CVE-2025-24500
HIGH
Broadcom Symantec Privileged Access Management 3.4.6-4.1.7 and 4.2.0 - Unauthenticated Information Disclosure
CVE-2025-24099
MEDIUM
macOS < 13.7.3, < 14.7.3, < 15.3 - Privilege Escalation
CVSS 5.1
CVE-2025-24479
HIGH
Rockwell FactoryTalk View ME <V15 - Local Privileged Command Execution
CVE-2025-23054
MEDIUM
HPE Aruba Networking Fabric Composer 7.0.0-7.1.0 - Authenticated Incorrect Authorization
CVSS 6.5
CVE-2025-23053
MEDIUM
HPE Aruba Networking Fabric Composer 7.0.0-7.1.0 - Authenticated Privilege Escalation via Web Management Interface
CVSS 6.5
CVE-2025-0781
HIGH
simgear < 2020.3.19 - Unauthenticated Arbitrary File Write via Nasal Script Sandbox Bypass
CVSS 8.6
CVE-2025-24141
LOW
iPadOS < 18.3 - Unauthenticated Photos Access via Locked App Bypass
CVSS 3.3
CVE-2025-24121
LOW
macOS < 13.7.3, < 14.7.3, < 15.3 - Unauthorized File System Modification
CVSS 3.3
CVE-2025-24114
MEDIUM
macOS < 13.7.3, < 14.7.3, < 15.3 - Unauthorized File System Modification
CVSS 5.5
CVE-2025-24401
MEDIUM
Jenkins Folder-based Authorization Strategy Plugin < 217.vd5b_18537403e - Incorrect Authorization
CVSS 6.8
CVE-2025-24400
MEDIUM
Jenkins Eiffel Broadcaster Plugin 2.8.0-2.10.2 - Incorrect Authorization via Credential ID Cache Key
CVSS 4.3
CVE-2025-24397
MEDIUM
Jenkins GitLab Plugin < 1.9.6 - Incorrect Authorization via Global Item/Configure Permission
CVSS 4.3
CVE-2025-21570
MEDIUM
Oracle Life Sciences Argus Safety 8.2.3 - Unauthenticated Incorrect Authorization in Login Component
CVSS 6.1
CVE-2025-21569
MEDIUM
Oracle Hyperion Data Relationship Management 11.2.19.0.000 - Incorrect Authorization in Web Services
CVSS 6.6
CVE-2025-21568
MEDIUM
Oracle Hyperion Data Relationship Management 11.2.19.0.000 - Unauthorized Data Access via Access and Security Component
CVSS 4.5
CVE-2025-21567
MEDIUM
MySQL Server < 9.1.0 - Unauthorized Data Access via Privilege Misconfiguration
CVSS 4.3
CVE-2025-21565
HIGH
Oracle Agile PLM Framework 9.3.6 - Unauthenticated Incorrect Authorization via HTTP
CVSS 7.5
CVE-2025-21563
MEDIUM
Oracle PeopleSoft Enterprise CC Common Application Objects 9.2 - Incorrect Authorization in Run Control Management
CVSS 4.3
Details
Vulnerabilities
3,064
Exploit Likelihood
High