CWE-862
8,736 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,736)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read permission to read the contents of a Groovy script by knowing its ID. |
1Relyum 2Rely Pcie Firmware Rely Rec FirmwareJun 17, 2026 Dec 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged user to execute administrative functions. |
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application |
2Quarkus Redhat2Build Of Quarkus QuarkusJun 17, 2026 Dec 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the en...Show more |
In ppcfw_enable of ppcfw.c, there is a possible EoP due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...Show more |
In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data. |
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7...Show more |
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2...Show more |
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2...Show more |
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7...Show more |
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8....Show more |
1Myprestamodules 1Orders (csv, Excel) Export Pro Jun 17, 2026 Dec 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can...Show more |
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality. |
In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges...Show more |
In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalati...Show more |
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Dec 4, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more |
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges need...Show more |
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |