CWE-862
10,075 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (10,075)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In opm service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In DMService, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes...Show more |
1Gallery Metabox Project 1Gallery Metabox Jun 17, 2026 Jul 12, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscribe...Show more |
1Gallery Metabox Project 1Gallery Metabox Jun 17, 2026 Jul 12, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subs...Show more |
The SAP BW BICS communication layer in SAP Business Warehouse and SAP BW/4HANA - version SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 730, SAP_BW 750, DW4CORE 100, DW4CORE 200, DW4CORE 300, may expose unauthorized cell val...Show more |
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the recieve_post, bmc_disconnect, name_post, and widget_post fu...Show more |
The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to a...Show more |
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action, allowing unauthenticated visitors to access private and password protected Events by guessing thei...Show more |
VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. |
In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can download personal informations without restriction formatted in json. |