← Back
CWE-862

8,735 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,735)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1H2o
1H2o
Jun 17, 2026
Nov 16, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This i...Show more
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require user interaction. The vulnerability can be exploited by making specific GET or POST requests to the ImportFiles and ParseSetup endpoints, respectively. This issue was identified in version 3.40.0.4 of h2o-3.Show less
1Webtechstreet
1Elementor Addon Elements
Jun 17, 2026
Nov 15, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the ajax_eae_post_data function. This can allow unauthenticated attackers to...Show more
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the ajax_eae_post_data function. This can allow unauthenticated attackers to extract sensitive data including post/page ids and titles including those of with pending/draft/future/private status.Show less
1Yugabyte
1Yugabytedb
Jun 17, 2026
Nov 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.
1Imagemapper Project
1Imagemapper
Jun 17, 2026
Nov 7, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'imgmap_delete_area_ajax' function in versions up to, and including, 1.2.6. This makes it possible...Show more
The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'imgmap_delete_area_ajax' function in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts and pages.Show less
1Tenda
1Rx9 Pro Firmware
Jun 17, 2026
Nov 7, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.
1Templately
1Templately
Jun 17, 2026
Nov 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.
1Gitlab
1Gitlab
Jun 17, 2026
Nov 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required ap...Show more
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.Show less
1Nationaledtech
1Boomerang
Jun 17, 2026
Nov 3, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticin...Show more
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.Show less
1Smartmodules
1Facebookconversiontrackingplus
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without rest...Show more
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer table such as name / surname / email.Show less
1Rcos
1Submitty
Jun 17, 2026
Nov 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed