CWE-862
9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (9,529)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions. |
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. |
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. |
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions. |
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions. |
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions. |
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. |
Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions. |
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions. |
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions. |
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. |
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. |
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions. |
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. |
Subscriber Broken Access Control in Tourfic <= 2.23.1 versions. |
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions. |
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions. |
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding...Show more |
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privile...Show more |
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and pu...Show more |