CWE-862
8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nttdocomo 1Wi Fi Station L 02f Firmware May 13, 2026 Sep 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Wi-Fi STATION L-02F Software version V10b and earlier allows remote attackers to bypass access restrictions to obtain information on device settings via unspecified vectors. |
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization |
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table. |
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table. |
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID,...Show more |
2Debian Postgresql2Debian Linux PostgresqlMay 13, 2026 Aug 16, 2017 N/A· v4 7.5 HIGH· v3 4.0 MEDIUM· v2 PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulti...Show more |
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The logout mechanism does not check for authorization. Therefore, an attacker only ne...Show more |
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler where a missing permissions check may allow users to gain access to arbitrary physical system memory, which may lead to an escal...Show more |
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object. |
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user may potentially escalate their privileges to root due to authorization checks not being perf...Show more |
1Rockwellautomation 1Panelview Plus 6 700 1500 Firmware May 13, 2026 Jun 14, 2017 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.00-20130325, 7.00-2013...Show more |
In environments that use external location for hive tables, Hive Authorizer in Apache Ranger before 0.7.1 should be checking RWX permission for create table. |
1Cisco 1Elastic Services Controller May 13, 2026 Jun 13, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local attacker to access information stored in the file system of an affected system, aka Unauthorized Dir...Show more |
1Cisco 1Prime Data Center Network Manager May 13, 2026 Jun 8, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary...Show more |
1Compulab 2Intense Pc Firmware Mintbox 2 FirmwareMay 13, 2026 Jun 6, 2017 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by l...Show more |
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Z...Show more |
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root. |
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory. |
1Cisco 1Prime Collaboration Provisioning May 13, 2026 May 22, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability...Show more |
1Cisco 1Prime Collaboration Provisioning May 13, 2026 May 18, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerabili...Show more |