CWE-862
8,721 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,721)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges. |
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
In phoneEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed. |
1Westerndigital 4My Cloud My Cloud HomeMy Cloud Os 5+1 moreJun 17, 2026 May 8, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 W...Show more |
The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, tvOS 16.4, watchOS 9.4. A shortcut may...Show more |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 May 7, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileFie...Show more |
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group membe...Show more |