CWE-862
8,681 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (8,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Franklinfueling 1Ts 550 Evo Firmware May 13, 2026 May 1, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization c...Show more |
1Franklinfueling 1Ts 550 Evo Firmware May 13, 2026 May 1, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an...Show more |
1Tp Link 2C20i Firmware C2 FirmwareMay 13, 2026 Apr 25, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked on any interface. |
1Deepin 1Deepin Desktop Environment May 13, 2026 Apr 10, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function through D-Bus. Anybody can change the g...Show more |
An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels. This issue is rated as Moderate because it could be u...Show more |
1Cisco 2Firepower Extensible Operating System Unified Computing SystemMay 13, 2026 Apr 7, 2017 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the debug plug-in functionality of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow...Show more |
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so. |
2Opensuse Postfixadmin Project2Leap PostfixadminMay 13, 2026 Mar 20, 2017 N/A· v4 2.7 LOW· v3 3.5 LOW· v2 The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check. |
lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check. |
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-es...Show more |
1Cisco 1Anyconnect Secure Mobility Client May 13, 2026 Feb 9, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the S...Show more |
1Sendquick 2Avera Sms Gateway Firmware Entera Sms Gateway FirmwareMay 13, 2026 Feb 5, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access control of the request which could result in an attacker being able to shutdown the system. |
The WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify authorization for private SET IOCTL cal...Show more |
1Sap 1Netweaver Application Server Java May 6, 2026 Apr 8, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other...Show more |
The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command. |
The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files vi...Show more |
1Mevin 1Basic Php Events Lister Apr 23, 2026 Sep 11, 2009 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administ...Show more |
The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, whic...Show more |
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors. |
The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unaut...Show more |