CWE-862
8,705 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,705)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
In power management service, there is a missing permission check. This could lead to set up power management service with no additional execution privileges needed. |
Improper access control in Key-Value RBAC in StackStorm version 3.7.0 didn't check the permissions in Jinja filters, allowing attackers to access K/V pairs of other users, potentially leading to the exposure of sensitive...Show more |
1Kyocera 38Ecosys M2535dn Firmware Ecosys M6526cdn FirmwareEcosys M6526cidn Firmware+35 moreJun 17, 2026 Dec 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Missing authorization vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to alter the product settings without authentication by sending a specially crafted...Show more |
RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH service port to disrupt service. |
The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to b...Show more |
1Theme And Plugin Translation For Polylang Project 1Theme And Plugin Translation For Polylang Jun 17, 2026 Nov 28, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.2.16 due to missing capability checks in the process_polylang_theme_translation_wp_loaded() function...Show more |
org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profil...Show more |
org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to...Show more |
CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts. |
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. T...Show more |
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code e...Show more |
1Codepeople 1Appointment Booking Calendar Jun 17, 2026 Nov 18, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress. |
Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress. |
1Zohocorp 1Manageengine Supportcenter Plus Jun 17, 2026 Nov 17, 2022 N/A· v4 3.3 LOW· v3 N/A· v2 Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list. |
HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services for HTTP or RPC endpoints used by the UI. Fixed in 1.14.0. |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Nov 15, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to m...Show more |
A missing permission check in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics. |