CWE-862
8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions. |
Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions. |
Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions. |
Subscriber Broken Access Control in Motors < 1.4.107 versions. |
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions. |
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions. |
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions. |
Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions. |
Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions. |
Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions. |
Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions. |
Subscriber Broken Access Control in Bookify <= 1.1.1 versions. |
Subscriber Broken Access Control in bunny.net <= 2.3.6 versions. |
Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension valid...Show more |
Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: from 1.0.0.262...Show more |
Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions. |
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects MasterStudy LMS Pro: from n/a before 4.7.16. |
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. An authenticated attacker with minimal privileges can access endpoints t...Show more |
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can o...Show more |
OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated callers to bypass intended command restrictions. Attackers can reach the af...Show more |