← Back
CWE-862

8,698 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,698)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Fedoraproject
LinuxRedhat
263scale Api Management
Codeready Linux BuilderEnterprise Linux+23 more
Jun 17, 2026
Mar 4, 2022
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape.Show less
1Elastic
1Kibana
Jun 17, 2026
Mar 3, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However...Show more
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A user with this privilege would be able to create new alerting rules or overwrite existing ones. However, any new or modified rules would not be enabled, and a user with this privilege could not modify alerting connectors. This effectively means that Read users could disable existing alerting rules.Show less
6Canonical
DebianFedoraproject+3 more
37Bootstrap Os
Codeready Linux BuilderCodeready Linux Builder For Power Little Endian+34 more
Jun 17, 2026
Mar 3, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to esca...Show more
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.Show less
1Pagerduty
1Rundeck
Jun 17, 2026
Feb 28, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendar...Show more
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendars, without appropriate authorization. Modifying or removing calendars could cause Scheduled Jobs to execute, or not execute on desired calendar days. Severity depends on trust level of authenticated users and impact of running or not running scheduled jobs on days governed by calendar definitions. Version 3.4.5 contains a patch for this issue. There are currently no known workarounds.Show less
1Madewithfuel
1Customize Wordpress Emails And Alerts
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-ma...Show more
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).Show less
2Codepress
Plugins Market
2Visitor Statistics
Wp Visitor Statistics (real Time Traffic)
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in us...Show more
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack of validation, sanitisation and escaping, users could set a malicious value and perform Cross-Site Scripting attacks against logged in adminShow less
1Wpgooglemap
1Wp Google Map
Jun 17, 2026
Feb 28, 2022
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitra...Show more
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.Show less
1Dineshkarki
1Use Any Font
Jun 17, 2026
Feb 28, 2022
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to sent arbitrary CSS which will then be processed by the...Show more
The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to sent arbitrary CSS which will then be processed by the frontend for all users. Due to the lack of sanitisation and escaping in the backend, it could also lead to Stored XSS issuesShow less
1Infornweb
1Logo Showcase With Slick Slider
Jun 17, 2026
Feb 28, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change...Show more
The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description, alt text, and URL of arbitrary uploaded media.Show less
1Waline
1Waline
Jun 17, 2026
Feb 25, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
1Framasoft
1Peertube
Jun 17, 2026
Feb 23, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
1Wpdevart
1Coming Soon And Maintenance Mode
Jun 17, 2026
Feb 21, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber...Show more
The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its coming_soon_send_mail AJAX action, allowing any authenticated users, with a role as low as subscriber to send arbitrary emails to all subscribed usersShow less
1Wpdevart
1Duplicate Page Or Post
Jun 17, 2026
Feb 21, 2022
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such...Show more
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issuesShow less
1Sourcegraph
1Sourcegraph
Jun 17, 2026
Feb 18, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restric...Show more
Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is patched in Sourcegraph version 3.37. As a workaround, ensure that requests to gitserver are properly protected.Show less
1Redis
1Redis
Jun 17, 2026
Feb 18, 2022
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
2Fedoraproject
Samba
2Fedora
Samba
Jun 17, 2026
Feb 18, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.
1Snipeitapp
1Snipe It
Jun 17, 2026
Feb 16, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
1Jenkins
1Swamp
Jun 17, 2026
Feb 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials.
1Jenkins
1Chef Sinatra
Jun 17, 2026
Feb 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML respons...Show more
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.Show less
1Jenkins
1Dbcharts
Jun 17, 2026
Feb 15, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials.