CWE-862
8,698 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,698)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject LinuxRedhat263scale Api Management Codeready Linux BuilderEnterprise Linux+23 moreJun 17, 2026 Mar 4, 2022 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more |
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However...Show more |
6Canonical DebianFedoraproject+3 more37Bootstrap Os Codeready Linux BuilderCodeready Linux Builder For Power Little Endian+34 moreJun 17, 2026 Mar 3, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to esca...Show more |
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendar...Show more |
1Madewithfuel 1Customize Wordpress Emails And Alerts Jun 17, 2026 Feb 28, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-ma...Show more |
2Codepress Plugins Market2Visitor Statistics Wp Visitor Statistics (real Time Traffic)Jun 17, 2026 Feb 28, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in us...Show more |
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitra...Show more |
The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to sent arbitrary CSS which will then be processed by the...Show more |
1Infornweb 1Logo Showcase With Slick Slider Jun 17, 2026 Feb 28, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change...Show more |
In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address. |
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0. |
1Wpdevart 1Coming Soon And Maintenance Mode Jun 17, 2026 Feb 21, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber...Show more |
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such...Show more |
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restric...Show more |
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution. |
2Fedoraproject Samba2Fedora SambaJun 17, 2026 Feb 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets. |
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11. |
A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials. |
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML respons...Show more |
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials. |