VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2025-64268High· 7.5
9mo ago

Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through <= 1.0.44.

Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Timetics: from n/a through <= 1.0.44.

▾ TwilightEPSS 0.34%via NVD
CVE-2025-64209High· 7.5
9mo ago

Missing Authorization vulnerability in StylemixThemes Masterstudy masterstudy allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy: from n/a through < 4.8.122.

Missing Authorization vulnerability in StylemixThemes Masterstudy masterstudy allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Masterstudy: from n/a through < 4.8.122.

▾ TwilightEPSS 0.34%via NVD
CVE-2020-36890High· 7.2
9mo ago

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user privileges via unauthorized requests. Attackers could potentially compromise global administrator accounts and invalida…

▾ Twilightkentico · xperienceEPSS 0.34%via NVD
CVE-2025-65036High· 8.3
9mo ago

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages without checking for permissions, which can lead to remote co…

▾ Twilightxwiki · pro_macrosEPSS 0.40%via NVD
CVE-2025-12876Medium· 5.3
9mo ago

The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pto_delete_file AJAX action in all versions up to, and including, 5.1.19

The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pto_delete_file AJAX action in all versions up to, and including, 5.1.19. Thi…

▾ SunlitEPSS 0.34%via NVD
CVE-2025-12165Medium· 4.3
9mo ago

The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webcake_save_config' AJAX endpoint in all versions up to, and including, 1.1

The Webcake – Landing Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'webcake_save_config' AJAX endpoint in all versions up to, and including, 1.1. This makes…

▾ SunlitEPSS 0.24%via NVD
CVE-2025-12133Medium· 4.3
9mo ago

The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_eprolo_delete_tracking and wp_ajax_eprolo_save_tracking_data AJAX endpoints in all versions …

The EPROLO Dropshipping plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wp_ajax_eprolo_delete_tracking and wp_ajax_eprolo_save_tracking_data AJAX endpoints in all versions …

▾ SunlitEPSS 0.22%via NVD
CVE-2025-13313Critical· 9.8
9mo ago

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due to missing authorization and authentication checks on the `ntzcrm_changepassword` AJ…

▾ MidnightEPSS 0.55%via NVD
CVE-2025-13312Medium· 5.3
9mo ago

The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all versions up to, and including, 2.5

The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capability check on the 'ntzcrm_add_new_tag' function in all versions up to, and including, 2.5. This makes it possible for u…

▾ SunlitEPSS 0.27%via NVD
CVE-2025-54159High· 7.5
9mo ago

Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors.

Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitrary files via unspecified vectors.

▾ Twilightsynology · beedriveEPSS 0.41%via NVD
CVE-2025-2848Medium· 6.3
9mo ago

A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.

A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.

▾ Sunlitsynology · mail_serverEPSS 0.37%via NVD
CVE-2025-13828None
10mo ago

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the pla…

SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the pla…

▾ SunlitEPSS 0.25%via NVD
CVE-2025-13813Medium· 5.6
10mo ago

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The atta…

▾ Sunlitmogublog_project · mogublogEPSS 0.47%via NVD
CVE-2025-13790Medium· 4.3
10mo ago

A vulnerability was determined in Scada-LTS up to 2.7.8.1

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be ut…

▾ Sunlitscada-lts · scada-ltsEPSS 0.26%via NVD
CVE-2025-10938Medium· 6.5
10mo ago

The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08

The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it po…

▾ Sunlitadmintwentytwenty · UiPress lite | Effortless custom dashboards, admin themes and pagesEPSS 0.25%via NVD
CVE-2025-11003Medium· 6.4
10mo ago

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up t…

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up t…

▾ Sunlitadmintwentytwenty · UiPress lite | Effortless custom dashboards, admin themes and pagesEPSS 0.21%via NVD
CVE-2025-52670Medium· 6.5
10mo ago

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.32%via NVD
CVE-2025-30398High· 8.1
10mo ago

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

▾ Twilightmicrosoft · nuance_powerscribe_360EPSS 0.79%via NVD
CVE-2025-8999Medium· 5.3
1y ago

The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' function in all versions up to, and including, 2.56

The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' function in all versions up to, and including, 2.56. This makes it possible for authenticated a…

▾ SunlitEPSS 0.28%via NVD
CVE-2024-32589High· 7.1
1y ago

Missing Authorization vulnerability in Dmitry V

Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders.This issue affects Barcode Scanner with Inventory & …

▾ TwilightEPSS 0.17%via NVD
CVE-2025-58334High· 8.1
1y ago

In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

▾ Twilightjetbrains · ide_servicesEPSS 0.29%via NVD
CVE-2025-54734Medium· 5.8
1y ago

Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Slider: from n/a through <= 1.1.30.

Missing Authorization vulnerability in bPlugins B Slider b-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Slider: from n/a through <= 1.1.30.

▾ SunlitEPSS 0.22%via NVD
CVE-2025-54733Medium· 6.5
1y ago

Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All Bootstrap Blocks: from n/a through <= 1.…

Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All Bootstrap Blocks: from n/a through <= 1.…

▾ SunlitEPSS 0.24%via NVD
CVE-2025-54714High· 7.1
1y ago

Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.201.

Missing Authorization vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zephyr Project Manager: from n/a through <= 3.3.201.

▾ TwilightEPSS 0.22%via NVD
CVE-2025-54710High· 7.1
1y ago

Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Tiktok Feed: from n/a through <= 1.0.21.

Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Tiktok Feed: from n/a through <= 1.0.21.

▾ TwilightEPSS 0.24%via NVD
CVE-2025-53337Medium· 5.4
1y ago

Missing Authorization vulnerability in Ashan Perera LifePress lifepress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LifePress: from n/a through <= 2.1.3.

Missing Authorization vulnerability in Ashan Perera LifePress lifepress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LifePress: from n/a through <= 2.1.3.

▾ SunlitEPSS 0.22%via NVD
CVE-2025-53341Medium· 4.3
1y ago

WordPress Stratus theme <= 4.2.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in Pixel Makers Creative INC. App, SaaS & Software Startup Tech Theme - Stratus allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects App, SaaS & Software Startup…

▾ SunlitPixel Makers Creative INC. · App, SaaS & Software Startup Tech Theme - StratusEPSS 0.24%via CVEORG
CVE-2025-5521Medium· 4.3
1y ago

A vulnerability was found in WuKongOpenSource WukongCRM 9.0

A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/user/updataPassword. The manipulation leads to cross-site re…

▾ Sunlit5kcrm · wukong_crmEPSS 0.31%via NVD
CVE-2023-44227High· 7.5
2y ago

Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a through 6.1.9.

Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a through 6.1.9.

▾ TwilightEPSS 0.56%via NVD
CVE-2024-32532Medium· 5.3
2y ago

Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6.

Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6.

▾ SunlitEPSS 0.52%via NVD
CWE-862 vulnerabilities (CVEs) — page 44 · VulnSea