CWE-862
8,683 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,683)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users. |
1Xinheinformation 1Xinhe Teaching Platform System Jun 17, 2026 Oct 15, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL par...Show more |
Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 and Nike App for iOS versions prior to 2.177.1 allows a remote attacker to lead a user to access an ar...Show more |
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail"...Show more |
Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids parameter in files-edit.php and id parameter in process.php function, a user with uploader role can...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Oct 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
1Maianscriptworld 1Maian Cart Jun 17, 2026 Oct 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin. |
In getDefaultSmsPackage of RoleManagerService.java, there is a possible way to get information about the default sms app of a different device user due to a missing permission check. This could lead to local information...Show more |
In sendAccessibilityEvent of NotificationManagerService.java, there is a possible disclosure of notification data due to a missing permission check. This could lead to local information disclosure with User execution pri...Show more |
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...Show more |
In system properties, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not...Show more |
2Fedoraproject Grafana2Fedora GrafanaJun 17, 2026 Oct 5, 2021 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/sn...Show more |
ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endpoints: /archibus/schema/ab-edit-users.axvw, /archibus/schema/ab-data-di...Show more |
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation. |
1Paymentplugins 1Stripe For Woocommerce Jun 17, 2026 Oct 4, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes/admin/class-wc-stripe-admin-user-edit.php file that makes it possible for attackers to configure th...Show more |
1Baicloud Cms Project 1Baicloud Cms Jun 17, 2026 Sep 30, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php. |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Sep 29, 2021 N/A· v4 8.8 HIGH· v3 6.1 MEDIUM· v2 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more |
Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information. |
1S Cms 1Cms Enterprise Website Construction System Jun 17, 2026 Sep 27, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the backgro...Show more |
1Wpdeveloper 1Countdown Block Jun 17, 2026 Sep 27, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, which allows any authenticated user, such as Subscriber, to modify post contents displayed to users. |