CWE-862
8,733 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,733)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if...Show more |
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to clear the SQS queue. |
A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins. |
Cerebrate before 1.15 lacks the Secure attribute for the session cookie. |
The Profile Builder WordPress plugin before 3.9.8 lacks authorisation and CSRF in its page creation function which allows unauthenticated users to create the register, log-in and edit-profile pages from the plugin on the...Show more |
In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploit...Show more |
In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for expl...Show more |
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed fo...Show more |
In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed fo...Show more |
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges |
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges |
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges |
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges |
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges |
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges |
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges |
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges |
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges |
In vowifiservice, there is a possible missing permission check.This could lead to local denial of service with no additional execution privileges |
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges |