← Back
CWE-862

8,683 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (8,683)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ninjaforms
1Ninja Forms
Jun 17, 2026
Sep 22, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows auth...Show more
The Ninja Forms WordPress plugin is vulnerable to arbitrary email sending via the trigger_email_action function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to send arbitrary emails from the affected server via the /ninja-forms-submissions/email-action REST API which can be used to socially engineer victims.Show less
1Ninjaforms
1Ninja Forms
Jun 17, 2026
Sep 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This...Show more
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information.Show less
1Ffw
1Omgf
Jun 17, 2026
Sep 20, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on...Show more
The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.Show less
1Bootstrapped
1Visual Link Preview
Jun 17, 2026
Sep 20, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscrib...Show more
The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URLShow less
1Sap
1Business One
Jun 17, 2026
Sep 15, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricted to specific users. For an attacker to discover the vulnerable functio...Show more
The Service Layer of SAP Business One, version - 10.0, allows an authenticated attacker to invoke certain functions that would otherwise be restricted to specific users. For an attacker to discover the vulnerable function, no in-depth system knowledge is required. Once exploited via Network stack, the attacker may be able to read, modify or delete restricted data. The impact is that missing authorization can result of abuse of functionality usually restricted to specific users.Show less
1Elastic
1Enterprise Search
Jun 17, 2026
Sep 15, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize A...Show more
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate route. Using this vulnerability, an authenticated attacker could utilize API keys belonging to higher privileged users.Show less
1Elastic
1Elasticsearch
Jun 17, 2026
Sep 15, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining access to information that they are unauthorized to view.
1Travis Ci
1Travis Ci
Jun 17, 2026
Sep 14, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpected sharing that is not specified by the customer-controlled .travis.yml file. In particular, the d...Show more
The activation process in Travis CI, for certain 2021-09-03 through 2021-09-10 builds, causes secret data to have unexpected sharing that is not specified by the customer-controlled .travis.yml file. In particular, the desired behavior (if .travis.yml has been created locally by a customer, and added to git) is for a Travis service to perform builds in a way that prevents public access to customer-specific secret environment data such as signing keys, access credentials, and API tokens. However, during the stated 8-day interval, secret data could be revealed to an unauthorized actor who forked a public repository and printed files during a build process.Show less
1Sap
1Erp Financial Accounting
Jun 17, 2026
Sep 14, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attack...Show more
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to.Show less
1Sap
1Netweaver Application Server Java
Jun 17, 2026
Sep 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.
1Linecorp
1Central Dogma
Jun 17, 2026
Sep 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.
1Abb
1Base Software
Jun 17, 2026
Sep 8, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .
1Apple
2Mac Os X
Macos
Jun 17, 2026
Sep 8, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may hav...Show more
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..Show less
1Apple
2Mac Os X
Macos
Jun 17, 2026
Sep 8, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report t...Show more
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..Show less
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Sep 8, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
This issue was addressed with improved checks. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to access notes from the lock screen.
1Hashicorp
1Consul
Jun 17, 2026
Sep 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.
1Comprotech
4Ip570 Firmware
Ip60 FirmwareIp70 Firmware+1 more
Jun 17, 2026
Sep 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.
1Comprotech
4Ip570 Firmware
Ip60 FirmwareIp70 Firmware+1 more
Jun 17, 2026
Sep 1, 2021
N/A· v4
8.1 HIGH· v3
8.5 HIGH· v2
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.
1Unit4
1Mik.starlight
Jun 17, 2026
Aug 31, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
1Primekey
1Ejbca
Jun 17, 2026
Aug 25, 2021
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as...Show more
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.Show less