CWE-862
9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (9,529)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its...Show more |
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not i...Show more |
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally. |
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network. |
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted. |
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally. |
Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally. |
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network. |
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
Missing authorization in Microsoft Windows Search Component allows an authorized attacker to perform tampering locally. |
Missing authorization in Windows SMB Server allows an authorized attacker to disclose information locally. |
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. |
Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and...Show more |
The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens w...Show more |
snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across te...Show more |
Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does...Show more |
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation...Show more |