CWE-862
8,735 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,735)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This i...Show more |
1Webtechstreet 1Elementor Addon Elements Jun 17, 2026 Nov 15, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the ajax_eae_post_data function. This can allow unauthenticated attackers to...Show more |
Prometheus metrics are available without
authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment. |
The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'imgmap_delete_area_ajax' function in versions up to, and including, 1.2.6. This makes it possible...Show more |
Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device. |
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts. |
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required ap...Show more |
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticin...Show more |
1Smartmodules 1Facebookconversiontrackingplus Jun 17, 2026 Nov 2, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without rest...Show more |
Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter. |
In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed |
In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed |