CWE-862
10,099 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (10,099)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Ex...Show more |
1Intuitive Custom Post Order Project 1Intuitive Custom Post Order Jun 17, 2026 Feb 21, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ajax action, allowing any logged in user (with roles as low as Subscriber) to update the menu order |
No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags with...Show more |
A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtain...Show more |
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server. |
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is norma...Show more |
SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Feb 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privile...Show more |
In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled function module in the proprietary SAP solution enables an authenticated att...Show more |
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure. |
In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
In firewall service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. |
In log service, there is a missing permission check. This could lead to local denial of service in log service. |
In log service, there is a missing permission check. This could lead to local denial of service in log service. |
In log service, there is a missing permission check. This could lead to local denial of service in log service. |
In log service, there is a missing permission check. This could lead to local denial of service in log service. |
In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. |
In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed. |