CWE-862
8,702 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,702)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User inte...Show more |
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check. This could lead to loca...Show more |
In onCreateContextMenu of NetworkProviderSettings.java, there is a possible way for non-owner users to change WiFi settings due to a missing permission check. This could lead to local escalation of privilege with User ex...Show more |
In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed....Show more |
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User exe...Show more |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 Jun 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Financial Consolidation - version 1010,�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings. |
Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect confidentiality. |
The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected with a nonce, howev...Show more |
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments...Show more |
The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body |
1Enqueue Anything Project 1Enqueue Anything Jun 17, 2026 Jun 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low priv...Show more |
Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239 Tuleap does not properly verify authorizations when displaying the content of tracker report render...Show more |
1Files Download Delay Project 1Files Download Delay Jun 17, 2026 Jun 8, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action. |
Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API. |
Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application. |
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...Show more |
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitati...Show more |
1Content Mask Project 1Content Mask Jun 17, 2026 May 30, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. As a result,...Show more |
1Ibm 2Elastic Storage System Spectrum ScaleJun 17, 2026 May 24, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 19160...Show more |