CWE-862
9,844 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (9,844)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users...Show more |
The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.4.1. This is due to the plu...Show more |
The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the saveConfig() function in all versions up to, and including, 1.8.5. This makes it possible...Show more |
The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin...Show more |
The Popup and Slider Builder by Depicter – Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel plugin for WordPress is vulnerable to arbitrary file uploads due to a...Show more |
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability and validation chec...Show more |
The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'features_revert_option AJAX endpoint in all versions up to, and including, 0.0.2. This makes...Show more |
WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create leave or resignation records on behalf of other users. |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user'...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_archivo' in '/backend/api...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'email' in '/backend/api/user...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_user' in '/backend/api/bu...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'seguro' i...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_tp_denuncia' and 'id_soc...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/ap...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user'...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscar...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscar...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in...Show more |
1Canaldenuncia 1Canaldenuncia.app Jun 17, 2026 Nov 4, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user'...Show more |