← Back
CWE-862

10,089 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (10,089)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Megafeis
1Bofei Dbd+
Jun 17, 2026
Mar 21, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.
1Getshortcodes
1Shortcodes Ultimate
Jun 17, 2026
Mar 20, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve...Show more
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not validate the user meta to be retrieved via the user shortcode, allowing any authenticated users such as subscriber to retrieve arbitrary user meta (except the user_pass), such as the user email and activation key by default.Show less
1Getshortcodes
1Shortcodes Ultimate
Jun 17, 2026
Mar 20, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, a...Show more
The WordPress Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 5.12.8 does not ensure that posts to be displayed via some shortcodes are already public and can be accessed by the user making the request, allowing any authenticated users such as subscriber to view draft, private or even password protected posts. It is also possible to leak the password of protected postsShow less
1Dash10
1Oauth Server
Jun 17, 2026
Mar 20, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary...Show more
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.Show less
1Hashicorp
1Nomad
Jun 17, 2026
Mar 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.
1Hashicorp
1Nomad
Jun 17, 2026
Mar 14, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.
1Siemens
1Ruggedcom Crossbow
Jun 17, 2026
Mar 14, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow auth...Show more
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.3). The client query handler of the affected application fails to check for proper permissions for specific read queries. This could allow authenticated remote attackers to access data they are not authorized for.Show less
1Siemens
1Ruggedcom Crossbow
Jun 17, 2026
Mar 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This cou...Show more
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions when assigning groups to user accounts. This could allow an authenticated remote attacker to assign administrative groups to otherwise non-privileged user accounts.Show less
1Siemens
1Ruggedcom Crossbow
Jun 17, 2026
Mar 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an...Show more
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.2). The client query handler of the affected application fails to check for proper permissions for specific write queries. This could allow an authenticated remote attacker to perform unauthorized actions.Show less
1Ibexa
5Digital Experience Platform
Ez Platform KernelEzplatform Http Cache Fastly+2 more
Jun 17, 2026
Mar 12, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
1Google
1Android
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.