CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
10,777 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 6 of 216
- CVE-2024-0138CRITICALCVSS 9.8EG 9.82024-11-23
NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclo…
- CVE-2024-52382CRITICALCVSS 9.8EG 9.82024-11-14
Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: from n/a through <= 1.0.0.
- CVE-2024-10575CRITICALCVSS 9.8EG 9.82024-11-13
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.
- CVE-2024-10589CRITICALCVSS 9.8EG 9.82024-11-09
The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the import_settings() function in all versions up to, …
- CVE-2024-10586CRITICALCVSS 9.8EG 9.82024-11-09
The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possi…
- CVE-2024-48073CRITICALCVSS 9.8EG 9.82024-11-08
sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is responsible for updating the software in the HT3300 device, is given the execution mode of sudo NOPASSWD. This program …
- CVE-2024-50490CRITICALCVSS 9.8EG 9.82024-10-29
Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through <= 1.0.2.
- CVE-2024-50476CRITICALCVSS 9.8EG 9.82024-10-29
Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.
- CVE-2024-50475CRITICALCVSS 9.8EG 9.82024-10-29
Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a through <= 1.0.
- CVE-2024-48538CRITICALCVSS 9.8EG 9.82024-10-24
Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.
- CVE-2019-25217CRITICALCVSS 9.8EG 9.82024-10-16
The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and Local File Inclusion in versions up to, and including, 5.0.12 due to incorrect use of an access control attribute on t…
- CVE-2018-25105CRITICALCVSS 9.8EG 9.82024-10-16
The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to downloa…
- CVE-2024-21216CRITICALCVSS 9.8EG 9.82024-10-15
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with …
- CVE-2024-9707CRITICALCVSS 9.8EG 9.82024-10-11
The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. Th…
- CVE-2024-9234CRITICALCVSS 9.8EG 9.82024-10-11
The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() func…
- CVE-2024-8289CRITICALCVSS 9.8EG 9.82024-09-04
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privilege escalation/de-escalation and account takeover due to an insufficient capability check on the update_item_permiss…
- CVE-2024-7950CRITICALCVSS 9.8EG 9.82024-09-04
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Local File Inclusion, Arbitrary Settings Update, and User Creation in all versions up to, and including, 2.1.6 via s…
- CVE-2024-4259CRITICALCVSS 9.8EG 9.82024-09-03
Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Provided by Users. This issue affects AKOS (AkosCepVatandasService): before V2.0; AKOS (T…
- CVE-2024-4428CRITICALCVSS 9.8EG 9.82024-08-29
Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users. This issue affects Managment Portal: through 21.05.2024.
- CVE-2024-41730CRITICALCVSS 9.8EG 9.82024-08-13
In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in…
- CVE-2024-6806CRITICALCVSS 9.8EG 9.82024-07-22
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.
- CVE-2024-6636CRITICALCVSS 9.8EG 9.82024-07-20
The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possi…
- CVE-2024-6328CRITICALCVSS 9.8EG 9.82024-07-12
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due to insufficient verification on the 'phone' parameter of…
- CVE-2024-4898CRITICALCVSS 9.8EG 9.82024-06-12
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it…
- CVE-2024-31244CRITICALCVSS 9.8EG 9.82024-06-09
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
- CVE-2024-36246CRITICALCVSS 9.8EG 9.82024-05-31
Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered o…
- CVE-2024-2771CRITICALCVSS 9.8EG 9.82024-05-18
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint…
- CVE-2024-4223CRITICALCVSS 9.8EG 9.82024-05-16
The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible…
- CVE-2024-27939CRITICALCVSS 9.8EG 9.82024-05-14
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code…
- CVE-2024-25912CRITICALCVSS 9.8EG 9.82024-04-11
Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
- CVE-2024-23752CRITICALCVSS 9.8EG 9.82024-01-22
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides…
- CVE-2023-6875CRITICALCVSS 9.8EG 9.82024-01-11
The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app …
- CVE-2023-47458CRITICALCVSS 9.8EG 9.82024-01-02
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.
- CVE-2023-5877CRITICALCVSS 9.8EG 9.82024-01-01
The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrar…
- CVE-2023-47754CRITICALCVSS 9.8EG 9.82023-12-19
Missing Authorization vulnerability in Clever plugins Delete Duplicate Posts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Delete Duplicate Posts: from n/a through 4.8.9.
- CVE-2023-50976CRITICALCVSS 9.8EG 9.82023-12-18
Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.
- CVE-2023-48417CRITICALCVSS 9.8EG 9.82023-12-11
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application
- CVE-2023-49654CRITICALCVSS 9.8EG 9.82023-11-29
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.
- CVE-2023-5533CRITICALCVSS 9.8EG 9.82023-10-20
The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and including, 4.8.9 as well as 4.9.2. This makes it possible for unau…
- CVE-2023-20252CRITICALCVSS 9.8EG 9.82023-09-27
A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vu…
- CVE-2023-43135CRITICALCVSS 9.8EG 9.82023-09-20
There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to t…
- CVE-2023-43134CRITICALCVSS 9.8EG 9.82023-09-20
There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend manag…
- CVE-2023-39073CRITICALCVSS 9.8EG 9.82023-09-12
An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.
- CVE-2023-40309CRITICALCVSS 9.8EG 9.82023-09-12
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of…
- CVE-2023-36140CRITICALCVSS 9.8EG 9.82023-09-11
In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.
- CVE-2023-3956CRITICALCVSS 9.8EG 9.82023-07-27
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. Th…
- CVE-2023-26301CRITICALCVSS 9.8EG 9.82023-07-21
Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege and/or Information Disclosure related to a lack of authentication with certain endpoints.
- CVE-2023-3076CRITICALCVSS 9.8EG 9.82023-07-10
The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's …
- CVE-2021-4381CRITICALCVSS 9.8EG 9.82023-06-07
The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, …
- CVE-2021-4370CRITICALCVSS 9.8EG 9.82023-06-07
The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and inc…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →