CWE-862
9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (9,529)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache McafeeNetapp3Cloud Backup Epolicy OrchestratorHttp ServerJun 17, 2026 Jun 10, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Jun 9, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticate...Show more |
In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially gain unauthorized access to TPM non-volatile memory. NOTE: Upgrading to firmware version 7.4.0.1 wi...Show more |
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured...Show more |
Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1.8.2 allows another authenticated users to access mail metadata of other users. Versions 1.4.3 and 1...Show more |
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to...Show more |
A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack....Show more |
1Citrix 1Sharefile Storagezones Controller Jun 17, 2026 May 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller. |
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related info...Show more |
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system,...Show more |
1Ibm 2Planning Analytics Cloud Planning Analytics LocalJun 17, 2026 May 17, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A r...Show more |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandw...Show more |
1F5 2Big Ip Advanced Web Application Firewall Big Ip Application Security ManagerJun 17, 2026 May 10, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, and 14.1.x before 14.1.4, BIG-IP Advanced WAF and ASM are missing authorization checks for file uploads to a specific directory within the REST API which might al...Show more |
1Remotemouse 1Emote Remote Mouse Jun 17, 2026 May 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with no prior authorization or authentication. |
1Vmware 1Vrealize Business For Cloud Jun 17, 2026 May 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised rem...Show more |
The ConfigFileAction component of U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to read arbitrary files via the ConfigName parameter. |
U.S. National Security Agency (NSA) Emissary 5.9.0 allows an authenticated user to delete arbitrary files. |
Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php. |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 May 6, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to ga...Show more |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 May 6, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to ga...Show more |