← Back
CWE-862

9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High

Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (9,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ttlock
1Ttlock
Jun 17, 2026
Sep 10, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is unavailable.
1Gitlab
1Gitlab
Jun 17, 2026
Sep 9, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.
1Youphptube
1Youphptube
Jun 17, 2026
Sep 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.
1Linuxfoundation
1Harbor
Jun 17, 2026
Sep 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. F...Show more
core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.Show less
1Totaljs
1Total.js Cms
Jun 17, 2026
Sep 5, 2019
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag cont...Show more
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>Show less
1Totaljs
1Total.js Cms
Jun 17, 2026
Sep 5, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only...Show more
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only for the front-end resource path, not for API requests. This leads to vertical and horizontal privilege escalation.Show less
1Wpbrigade
1Loginpress
Jun 17, 2026
Sep 3, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
2Androvideo
Geovision
3Gv Vd8700 Firmware
Gv Vr360 FirmwareVd 1 Firmware
Jun 17, 2026
Aug 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.
1Kubernetes
1Kubernetes
Jun 17, 2026
Aug 29, 2019
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive infor...Show more
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.Show less
1Elearningfreak
1Insert Or Embed Articulate Content
Jun 17, 2026
Aug 27, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
1Obdev
1Little Snitch
Jun 17, 2026
Aug 23, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows d...Show more
Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows directory listings and copying files as root.Show less
1Atlassian
1Jira Server
Jun 17, 2026
Aug 23, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
1Google
1Android
Jun 17, 2026
Aug 20, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check. This could lead to local denial of access to Emergency Services with User execution privileges ne...Show more
In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check. This could lead to local denial of access to Emergency Services with User execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-132438333.Show less
1Eprosima
1Fast Rtps
Jun 17, 2026
Aug 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partiti...Show more
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partition.Show less
1Rankmath
1Seo
Jun 17, 2026
Aug 15, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
1Microsoft
3Windows 10
Windows Server 2016Windows Server 2019
Jun 17, 2026
Aug 14, 2019
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elev...Show more
An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system. The security update addresses the vulnerability by preventing sandboxed processes from creating reparse points targeting inaccessible files.Show less
1Sap
1Advanced Business Application Programming Platform Kernel
Jun 17, 2026
Aug 14, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL...Show more
SAP Kernel (ABAP Debugger), versions KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, KRNL64UC 7.21, 7.21EXT, 7.22, 7.22EXT, 7.49, 7.73, KERNEL 7.21, 7.49, 7.53, 7.73, 7.75, 7.76, 7.77, allows a user to execute “Go to statement” without possessing the authorization S_DEVELOP DEBUG 02, resulting in Missing Authorization CheckShow less
1Metabox
1Meta Box
Jun 17, 2026
Aug 9, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=rwmb_delete_file attachment_id parameter.
1Jenkins
1Relution Enterprise Appstore Publisher
Jun 17, 2026
Aug 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to have Jenkins initiate an HTTP connection to an attacker-specified server.
1Jenkins
1Xl Testview
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-spec...Show more
A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.Show less