CWE-862
10,102 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (10,102)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed. |
The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any...Show more |
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 22, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This...Show more |
1Popup Manager Project 1Popup Manager Jun 17, 2026 Dec 19, 2022 N/A· v4 4.3 MEDIUM· v3 N/A· v2 The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them |
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their p...Show more |
The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information. |
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an unauthorized attacker to perform privileged actions through the execution of specific binaries listed in ADB daemon. The attacker must have physi...Show more |
In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User...Show more |
In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a new WiFi network due to a missing permission check. This could lead to local escalation of privilege...Show more |
In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privile...Show more |
In onOptionsItemSelected of ManageApplications.java, there is a possible bypass of profile owner restrictions due to a missing permission check. This could lead to local escalation of privilege with no additional executi...Show more |