CWE-862
8,727 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,727)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privile...Show more |
In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of pr...Show more |
A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through...Show more |
A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and to check for the existence of directories, `.cs...Show more |
A missing permission check in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. |
A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. |
A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another...Show more |
A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |
A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained thr...Show more |
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm. |
A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through anoth...Show more |
In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
1Unisoc 13S8000 Sc7731eSc9832e+10 moreJun 17, 2026 Jul 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In fastDial service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |