CWE-862
8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, The ValidateArgumentType RPC endpoint in service/internal/api/api.go does not perform any authentication or authori...Show more |
Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. |
Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions. |
Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions. |
Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions. |
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions. |
Subscriber Broken Access Control in Amelia <= 2.2 versions. |
Subscriber Broken Access Control in myCred <= 3.0.3 versions. |
Subscriber Broken Access Control in Groundhogg < 4.4.1 versions. |
Subscriber Broken Access Control in ChatBot <= 7.9.7 versions. |
Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions. |
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions. |
Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions. |
Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions. |
Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions. |
Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions. |
Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions. |
Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions. |
Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions. |
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions. |