CWE-862
9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (9,529)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Drupal 1Authenticated User Page Caching Nov 21, 2024 Feb 18, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to...Show more |
In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app...Show more |
VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorizatio...Show more |
SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive responses that may contain data read with user...Show more |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures. |
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in. |
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. |
Prototype 1.6.0.1 allows remote authenticated users to forge ticket creation (on behalf of other user accounts) via a modified email ID field. |
1Kronos 1Web Time And Attendance Jun 17, 2026 Jan 30, 2020 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate servlet allows an attacker with Timekeeper or Supervisor privileges to gain unauthorized administrativ...Show more |
Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH is part of the default workflow and is activated by default, requiring active user intervention of u...Show more |
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information. |
1Easytimestudio 1Easy File Manager Nov 21, 2024 Jan 24, 2020 N/A· v4 9.9 CRITICAL· v3 8.7 HIGH· v2 Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass |
In Gallagher Command Centre Server v8.10 prior to v8.10.1134(MR4), v8.00 prior to v8.00.1161(MR5), v7.90 prior to v7.90.991(MR5), v7.80 prior to v7.80.960(MR2) and v7.70 or earlier, an authenticated user connecting to OP...Show more |
1Jenkins 1Health Advisor By Cloudbees Jun 17, 2026 Jan 15, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient. |
A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials ID...Show more |
Missing authorization check in a transaction within SAP Leasing (update provided in SAP_APPL 6.18, EA-APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16 and 6.17). |
1Webfactoryltd 1Minimal Coming Soon & Maintenance Mode Jun 17, 2026 Jan 9, 2020 N/A· v4 7.6 HIGH· v3 6.5 MEDIUM· v2 A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with basic access to enable and disable maintenance-mode settings (impacting the availability and confidenti...Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Jan 8, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of exist...Show more |
1Business Alliance Financial Circle Project 1Business Alliance Financial Circle Nov 21, 2024 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is...Show more |