← Back
CWE-862

8,688 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,688)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Craterapp
1Crater
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.
1Apache
1Shenyu
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
1Apache
1Shenyu
Jun 17, 2026
Jan 25, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
1Themeum
1Qubely
Jun 17, 2026
Jan 24, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any au...Show more
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary postsShow less
1Etoilewebdesign
1Ultimate Faq
Jun 17, 2026
Jan 24, 2022
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, a...Show more
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questionsShow less
1Wp Experts
1Protect Wp Admin
Jun 17, 2026
Jan 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered)...Show more
The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted requestShow less
1Wasmcloud
1Host Runtime
Jun 17, 2026
Jan 21, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors...Show more
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for inbound invocations, but with this vulnerability actor capability claims are not verified upon receiving invocations. This compromises the security model for actors as they can receive unauthorized invocations from linked capability providers. The problem has been patched in versions `0.52.2` and greater. There is no workaround and users are advised to upgrade to an unaffected version as soon as possible.Show less
1Allwinnertech
1Android Q Sdk
Jun 17, 2026
Jan 19, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the caller's permission, in which a third-party app could change system settings.
1Deltarm
1Delta Rm
Jun 17, 2026
Jan 18, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk labels, such as Criticality and Priority Indication labels. By using the /core/table/query endpoint, a...Show more
An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk labels, such as Criticality and Priority Indication labels. By using the /core/table/query endpoint, and by using a POST request and indicating the affected label with tableUid parameter and the operation with datas[query], it is possible to edit, create, and delete the following labels: Priority Indication, Quality Evaluation, Progress Margin and Priority. Furthermore, it is also possible to export Criticality labels with an unprivileged user.Show less
1Vjinfotech
2Wp Import Export
Wp Import Export Lite
Jun 17, 2026
Jan 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download foun...Show more
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 18, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to...Show more
An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to unauthorized access to some particular fields through the GraphQL API.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 18, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying t...Show more
An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.Show less
1I Plugins
1Whmcs Bridge
Jun 17, 2026
Jan 18, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts,...Show more
The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the cc_whmcs_bridge_add_admin function, low-level authenticated users such as subscribers can exploit this vulnerability.Show less
1Theeventscalendar
1Eventcalendar
Jun 17, 2026
Jan 17, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
1Google
1Android
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...Show more
In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-192663648Show less
1Arista
1Eos
Jun 17, 2026
Jan 14, 2022
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
1Google
1Android
Jun 17, 2026
Jan 14, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for it. This lets apps keep track of what devices are paired without request...Show more
The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for it. This lets apps keep track of what devices are paired without requesting BLUETOOTH permissions.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-162951906Show less
1Snipeitapp
1Snipe It
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
1Trustedfirmware
1Trusted Firmware M
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no autho...Show more
Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a caller and a key owner.Show less
1Jenkins
1Publish Over Ssh
Jun 17, 2026
Jan 12, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-specified SSH server using attacker-specified credentials.