Vulnerabilities (CVE)

Filtered by CWE-862
Total 9949 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-46174 1 Ruoyi 1 Ruoyi 2026-06-17 N/A 7.5 HIGH
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.
CVE-2025-45854 1 Jehc 1 Jehc-bpm 2026-06-17 N/A 10.0 CRITICAL
/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
CVE-2025-44001 1 Mattermost 1 Confluence 2026-06-17 N/A 4.0 MEDIUM
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the Get Channel Subscriptions details endpoint.
CVE-2025-43977 1 Sktelecom 1 Com.skt.prod.dialer 2026-06-17 N/A 5.5 MEDIUM
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component.
CVE-2025-43976 1 Textnow 1 2ndline 2026-06-17 N/A 5.5 MEDIUM
The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component.
CVE-2025-43862 1 Langgenius 1 Dify 2026-06-17 N/A 7.6 HIGH
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allows non-admin users to make unauthorized access and changes on the APPSs. This issue has been patched in version 0.6.12. A workaround for this vulnerability involves updating the the access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can access Orchestration of the APPs.
CVE-2025-43838 2026-06-17 N/A 6.5 MEDIUM
Missing Authorization vulnerability in ChoPlugins.com Custom PC Builder Lite for WooCommerce custom-pc-builder-lite-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom PC Builder Lite for WooCommerce: from n/a through <= 1.0.1.
CVE-2025-43805 1 Liferay 2 Digital Experience Platform, Liferay Portal 2026-06-17 N/A 5.3 MEDIUM
Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not perform an authorization check when users attempt to view a display page template, which allows remote attackers to view display page templates via crafted URLs.
CVE-2025-43788 1 Liferay 2 Digital Experience Platform, Liferay Portal 2026-06-17 N/A 4.3 MEDIUM
The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
CVE-2025-43773 1 Liferay 2 Digital Experience Platform, Liferay Portal 2026-06-17 N/A 9.1 CRITICAL
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for improper access through the expandoTableLocalService.
CVE-2025-43720 1 H-mdm 1 Headwind Mdm 2026-06-17 N/A 6.5 MEDIUM
Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.
CVE-2025-43497 1 Apple 1 Macos 2026-06-17 N/A 5.2 MEDIUM
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to break out of its sandbox.
CVE-2025-43358 1 Apple 3 Ipados, Iphone Os, Macos 2026-06-17 N/A 8.8 HIGH
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A shortcut may be able to bypass sandbox restrictions.
CVE-2025-43341 1 Apple 1 Macos 2026-06-17 N/A 7.8 HIGH
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to gain root privileges.
CVE-2025-43331 1 Apple 1 Macos 2026-06-17 N/A 4.0 MEDIUM
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access protected user data.
CVE-2025-43329 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2026-06-17 N/A 8.8 HIGH
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, watchOS 26. An app may be able to break out of its sandbox.
CVE-2025-43318 1 Apple 1 Macos 2026-06-17 N/A 6.2 MEDIUM
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Tahoe 26. An app with root privileges may be able to access private information.
CVE-2025-43316 1 Apple 2 Macos, Visionos 2026-06-17 N/A 7.8 HIGH
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26, visionOS 26. A malicious app may be able to gain root privileges.
CVE-2025-43311 1 Apple 1 Macos 2026-06-17 N/A 5.1 MEDIUM
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to access protected user data.
CVE-2025-43286 1 Apple 1 Macos 2026-06-17 N/A 7.8 HIGH
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may be able to break out of its sandbox.