CWE-862
8,698 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,698)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jenkins 1Cloudbees Aws Credentials Jun 17, 2026 Mar 15, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token. |
The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it...Show more |
The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with the relevant capability (site administrators by default). Moodle versions 3.10 to 3.10.3 are affecte...Show more |
Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected. |
Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2. |
Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5. |
1Nextcloud 1Nextcloud Server Jun 17, 2026 Mar 10, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is abl...Show more |
1Sap 1Financial Consolidation Jun 17, 2026 Mar 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message. |
1Sap 1Netweaver Application Server Java Jun 17, 2026 Mar 10, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks. |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Mar 10, 2022 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an authenticated attacker, to access content on the start screen of any transaction that is available wi...Show more |
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed...Show more |
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...Show more |
In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more |
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4. |
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permi...Show more |
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enum...Show more |
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. |
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. |
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, whic...Show more |
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information dis...Show more |