← Back
CWE-862

8,707 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,707)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Dec 13, 2022
N/A· v4
2.3 LOW· v3
N/A· v2
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privile...Show more
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-231496105Show less
1Sap
1Netweaver Process Integration
Jun 17, 2026
Dec 13, 2022
N/A· v4
8.6 HIGH· v3
N/A· v2
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming a...Show more
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data across the entire system. This allows the attacker to have full read access to user data, make limited modifications to user data, and degrade the performance of the system, leading to a high impact on confidentiality and a limited impact on the availability and integrity of the application. Show less
1Sap
1Netweaver Process Integration
Jun 17, 2026
Dec 13, 2022
N/A· v4
9.4 CRITICAL· v3
N/A· v2
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to...Show more
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized operations. The vulnerability affects local users and data, leading to a considerable impact on confidentiality as well as availability and a limited impact on the integrity of the application. These operations can be used to: * Read any information * Modify sensitive information * Denial of Service attacks (DoS) * SQL Injection Show less
1Dpdgroup
1Woocommerce Shipping
Jun 17, 2026
Dec 12, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, whic...Show more
The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.Show less
1Welcart
1Welcart E Commerce
Jun 17, 2026
Dec 12, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods.
1Prestashop
1Prestashop
Jun 17, 2026
Dec 8, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without approp...Show more
PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users are advised to upgrade to version 1.7.8.8. There are no known workarounds for this issue.Show less
1Daloradius
1Daloradius
Jun 17, 2026
Dec 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.
1Ibm
1Content Navigator
Jun 17, 2026
Dec 7, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins...Show more
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805.Show less
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Dec 6, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed.