CWE-862
10,069 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (10,069)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2...Show more |
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2...Show more |
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7...Show more |
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8....Show more |
1Myprestamodules 1Orders (csv, Excel) Export Pro Jun 17, 2026 Dec 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can...Show more |
Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality. |
In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges...Show more |
In getCredentialManagerPolicy of DevicePolicyManagerService.java, there is a possible method for users to select credential managers without permission due to a missing permission check. This could lead to local escalati...Show more |
4Google LinuxfoundationOpenwrt+1 more4Android OpenwrtRdk B+1 moreJun 17, 2026 Dec 4, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...Show more |
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges need...Show more |
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
In camera service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
In power manager, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
In telecom service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed |
In telecom service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed |
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed |
In telecom service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed |
In engineermode service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges nee...Show more |