CWE-862
10,089 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (10,089)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests. |
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve...Show more |
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, a...Show more |
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary...Show more |
HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1. |
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1. |
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow auth...Show more |
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This cou...Show more |
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an...Show more |
1Ibexa 5Digital Experience Platform Ez Platform KernelEzplatform Http Cache Fastly+2 moreJun 17, 2026 Mar 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. |
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |