CWE-862
9,529 CVEs • Abstraction: Class • Likelihood of Exploit: High
Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVEs (9,529)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins. |
A missing permission check in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect...Show more |
1Canon 66Eos 1d C Firmware Eos 1d X FirmwareEos 1d X Mkii Firmware+63 moreJun 17, 2026 Aug 6, 2019 N/A· v4 6.5 MEDIUM· v3 4.8 MEDIUM· v2 Missing authorization vulnerability exists in EOS series digital cameras (EOS-1D X firmware version 2.1.0 and earlier, EOS-1D X MKII firmware version 1.1.6 and earlier, EOS-1D C firmware version 1.4.1 and earlier, EOS 5D...Show more |
1Eq 3 2Ccu2 Firmware Ccu3 FirmwareJun 17, 2026 Aug 6, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid guest level or user level account can create a new admin level account, read the service messages, clea...Show more |
1Eq 3 2Ccu2 Firmware Ccu3 FirmwareJun 17, 2026 Aug 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorization checks. An attacker can obtain a session ID from CVE-2019-9583, resulting in the ability to read...Show more |
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks. |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt wi...Show more |
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to. |
2Jenkins Redhat2Openshift Container Platform Pipeline\Jun 17, 2026 Jul 31, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by glo...Show more |
1Jenkins 1Configuration As Code Jun 17, 2026 Jul 31, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin contain...Show more |
2Canonical Redhat5Enterprise Linux LibvirtUbuntu Linux+2 moreJun 17, 2026 Jul 30, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of...Show more |
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events. |
2Netapp Redhat6Active Iq Unified Manager Jboss Data GridJboss Enterprise Application Platform+3 moreJun 17, 2026 Jul 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api. |
A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue on...Show more |
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems a...Show more |
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80. |
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php. |
zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php. |
MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure. The impact is: MySQL database content disclosure (e.g. username, password). The...Show more |
1Llnl 1Model Specific Registers Safe Jun 17, 2026 Jul 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The attack vector is: A...Show more |