Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-862 (授权机制缺失) — Vulnerability Class 5531

5531 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-64401 Apache OpenOffice: Remote documents loaded without prompt via IFrame — Apache OpenOffice 7.7 -2025-11-12
CVE-2025-12113 Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images <= 1.8.3 - Missing Authorization to Authenticated (Subscriber+) API Key Deletion — Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images 4.3 Medium2025-11-12
CVE-2025-12633 Booking Calendar | Appointment Booking | Bookit <= 2.5.0 - Missing Authorization to Unauthenticated Stripe Connection — Bookit — Booking & Appointment Calendar 7.5 High2025-11-12
CVE-2025-30398 Nuance PowerScribe 360 Information Disclosure Vulnerability — Nuance PowerScribe 360 version 4.0.1 8.1 High2025-11-11
CVE-2025-33185 NVIDIA AIStore 安全漏洞 — AuthN component of NVIDIA AIStore 5.3 Medium2025-11-11
CVE-2025-12953 Classified Listing – AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering — Classified Listing – AI-Powered Classified ads & Business Directory Plugin 4.3 Medium2025-11-11
CVE-2025-5317 Improper access restriction to critical folder in Bitdefender Endpoint Security Tools for Mac — Endpoint Security Tools for Mac 4.4 -2025-11-11
CVE-2025-11999 Add Multiple Marker <= 1.2 - Missing Authorization to Unauthenticated Settings Update — Multi Location Marker 5.3 Medium2025-11-11
CVE-2025-12665 Ninja Countdown <= 1.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Countdown Deletion — Ninja Countdown | Fastest Countdown Builder 4.3 Medium2025-11-11
CVE-2025-12526 Private Google Calendars <= 20250811 - Missing Authorization to Authenticated (Subscriber+) Settings Reset — Private Google Calendars 4.3 Medium2025-11-11
CVE-2025-11996 Find Unused Images <= 1.0.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion — Find Unused Images 5.3 Medium2025-11-11
CVE-2025-11988 Crypto Tool <= 2.22 - Missing Authentication to Unauthenticated Limited File Deletion — Crypto Tool 5.3 Medium2025-11-11
CVE-2025-11894 Shelf Planner <= 2.8.1 - Missing Authorization to Unauthenticated Settings Update — Shelf Planner Inventory Management for WooCommerce 5.3 Medium2025-11-11
CVE-2025-42899 Missing Authorization check in SAP S4CORE (Manage Journal Entries) — SAP S4CORE (Manage Journal Entries) 4.3 Medium2025-11-11
CVE-2025-42882 Missing Authorization check in SAP NetWeaver Application Server for ABAP — SAP NetWeaver Application Server for ABAP 4.3 Medium2025-11-11
CVE-2025-48878 Combodo iTop vulnerable to IDOR with ModuleInstallation object — iTop 4.3 Medium2025-11-10
CVE-2025-64684 JetBrains YouTrack 安全漏洞 — YouTrack 4.5 Medium2025-11-10
CVE-2025-64681 JetBrains Hub 安全漏洞 — Hub 2.7 Low2025-11-10
CVE-2025-12925 rymcu forest UserDicController.java deleteDic authorization — forest 7.3 High2025-11-10
CVE-2025-12924 rymcu forest BankController.java GlobalResult authorization — forest 4.3 Medium2025-11-10
CVE-2025-11448 Gallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion — Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More 4.3 Medium2025-11-08
CVE-2025-12498 EventPrime – Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation — EventPrime – Events Calendar, Bookings and Tickets 4.3 Medium2025-11-08
CVE-2025-7663 Ovatheme Events Manager <= 1.8.6 - Missing Authorization — Ovatheme Events Manager 6.5 Medium2025-11-08
CVE-2025-12042 Course Booking System <= 6.1.5 - Missing Authorization to Unauthenticated Booking Data Export — Course Booking System 5.3 Medium2025-11-08
CVE-2025-12167 Contact Form 7 AWeber Extension <= 0.1.42 - Missing Authorization to Authenticated (Subscriber+) Log Reset — Connect Contact Form 7 and AWeber 4.3 Medium2025-11-08
CVE-2025-12583 Simple Downloads List <= 1.4.3 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting — Simple Downloads List 6.4 Medium2025-11-08
CVE-2025-12527 Page & Post Notes <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Note Update/Deletion — Page & Post Notes 4.3 Medium2025-11-07
CVE-2025-4522 IDonate 2.0.0 - 2.1.9 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function — IDonate – Blood Donation, Request And Donor Management System 6.5 Medium2025-11-07
CVE-2025-5483 LC Wizard 1.2.10 - 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation — Connector Wizard (formerly LC Wizard) 8.1 High2025-11-07
CVE-2025-64323 kgateway is missing xDS authorization — kgateway 5.3 Medium2025-11-07

Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5531 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.