CWE-862
10,089 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (10,089)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. |
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the uucss_update_rule function in versions up to, and including, 1.7.1. This...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the attach_rule function in versions up to, and including, 1.7.1. This mak...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the clear_uucss_logs function in versions up to, and including, 1.7.1. This makes i...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check on the ajax_deactivate function in versions up to, and including, 1.7.1. This ma...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the ucss_connect function in versions up to, and including, 1.7.1. Thi...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized cache modification due to a missing capability check on the queue_posts function in versions up to, and including, 1.7.1. This mak...Show more |
1Rapidload 2Power Up For Autoptimize Rapidload Power Up For AutoptimizeJun 17, 2026 Mar 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_page_cache function in versions up to, and including, 1.7.1. This make...Show more |
A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader...Show more |
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins. |
metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authenti...Show more |
The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to missing capability checks on several AJAX actions. This makes it possibl...Show more |
The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress...Show more |
1Posimyth 1The Plus Addons For Elementor Jun 17, 2026 Mar 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders f...Show more |
The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes in versions up to, and including 1.4.1 due to a lack of proper capability checking on the backup_gu...Show more |