← Back
CWE-862

8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,681)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
5.8 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
-
-
Jul 14, 2026
Jun 26, 2026
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records...Show more
Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and modify or delete records across bases and tables via endpoints like GET /api/v2/tables/get and POST /api/v2/tables/updateRecords.Show less
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
8.3 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
-
-
Jun 29, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions.
-
-
Jun 29, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
-
-
Jun 26, 2026
Jun 26, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
1Jetbrains
1Youtrack
Jun 27, 2026
Jun 26, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings