CWE-862
8,707 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,707)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privile...Show more |
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming a...Show more |
1Sap 1Netweaver Process Integration Jun 17, 2026 Dec 13, 2022 N/A· v4 9.4 CRITICAL· v3 N/A· v2 An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to...Show more |
The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, whic...Show more |
The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing any logged-in user to create, update and delete shipping methods. |
PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without approp...Show more |
Missing Authorization in GitHub repository lirantal/daloradius prior to master branch. |
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins...Show more |
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure. |
In windows manager service, there is a missing permission check. This could lead to set up windows manager service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no additional execution privileges needed. |
In wlan driver, there is a possible missing permission check, This could lead to local information disclosure. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |