← Back
CWE-862

10,070 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (10,070)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Templately
1Templately
Jun 17, 2026
Nov 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.
1Gitlab
1Gitlab
Jun 17, 2026
Nov 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required ap...Show more
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.Show less
1Nationaledtech
1Boomerang
Jun 17, 2026
Nov 3, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticin...Show more
An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.Show less
1Smartmodules
1Facebookconversiontrackingplus
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without rest...Show more
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer table such as name / surname / email.Show less
1Rcos
1Submitty
Jun 17, 2026
Nov 2, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by modifying request parameter.
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
In sim service, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
1Google
1Android
Jun 17, 2026
Nov 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed