CWE-862
8,683 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,683)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack....Show more |
1Citrix 1Sharefile Storagezones Controller Jun 17, 2026 May 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller. |
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related info...Show more |
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system,...Show more |
1Ibm 2Planning Analytics Cloud Planning Analytics LocalJun 17, 2026 May 17, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A r...Show more |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandw...Show more |
1F5 2Big Ip Advanced Web Application Firewall Big Ip Application Security ManagerJun 17, 2026 May 10, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the REST API which might al...Show more |
1Remotemouse 1Emote Remote Mouse Jun 17, 2026 May 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with no prior authorization or authentication. |
1Vmware 1Vrealize Business For Cloud Jun 17, 2026 May 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised rem...Show more |
The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the ConfigName parameter. |
U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files. |
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php. |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 May 6, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to ga...Show more |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 May 6, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to ga...Show more |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 May 6, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to ga...Show more |
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 (fixed in 1.0.470/471 and 1.1.1) was discovered that has the same impact as CVE-2020-26231 & CVE-202...Show more |
1Recruit Holdings 1Hot Pepper Gourmet Jun 17, 2026 Apr 27, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Improper access control vulnerability in Hot Pepper Gourmet App for Android ver.4.111.0 and earlier, and for iOS ver.4.111.0 and earlier allows a remote attacker to lead a user to access an arbitrary website via the vuln...Show more |
Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and earlier allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. |
SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData service and manipulate the activation for the SAP EarlyWatch Alert servi...Show more |
1Sap 1Fiori Apps 2.0 For Travel Management In Sap Erp Jun 17, 2026 Apr 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authenticated but unauthorized attacker to read personnel numbers of employees, resulting in escalation o...Show more |