CWE-862
8,736 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,736)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user'...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_archivo' in '/backend/api...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'email' in '/backend/api/user...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_user' in '/backend/api/bu...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'seguro' i...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_tp_denuncia' and 'id_soc...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/ap...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user'...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscar...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscar...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user'...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/ap...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscar...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/ap...Show more |
The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function in all versions up to, and including, 1.6.2. Th...Show more |
The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up to, and including, 1.1.0. Thi...Show more |
The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabilities() function in all versions up to, and including, 1.0. This makes it...Show more |
The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_nopriv_reset_capability' AJAX endpoint in all versions up to, and inc...Show more |
The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_post_data() function i...Show more |