← Back
CWE-862

9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (9,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
-
-
Aug 14, 2026
Aug 13, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
1Postgresql
1Postgresql
Aug 29, 2026
Aug 13, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding...Show more
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.Show less
1Postgresql
1Postgresql
Aug 29, 2026
Aug 13, 2026
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privile...Show more
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.Show less
-
-
Aug 26, 2026
Aug 13, 2026
6.9 MEDIUM· v4
5.8 MEDIUM· v3
N/A· v2
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and pu...Show more
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous readers and publish-mode readers can obtain the complete bookmark vocabulary across the workspace, disclosing subject matter and organizational information from inaccessible documents.Show less