CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
10,777 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 7 of 216
- CVE-2021-4362CRITICALCVSS 9.8EG 9.82023-06-07
The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. Thi…
- CVE-2021-4346CRITICALCVSS 9.8EG 9.82023-06-07
The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible f…
- CVE-2021-4343CRITICALCVSS 9.8EG 9.82023-06-07
The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking r…
- CVE-2021-4341CRITICALCVSS 9.8EG 9.82023-06-07
The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and inclu…
- CVE-2020-36719CRITICALCVSS 9.8EG 9.82023-06-07
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions …
- CVE-2019-25141CRITICALCVSS 9.8EG 9.82023-06-07
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This …
- CVE-2023-31047CRITICALCVSS 9.8EG 9.82023-05-07
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageFi…
- CVE-2022-4939CRITICALCVSS 9.8EG 9.82023-04-05
THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership setti…
- CVE-2022-48367CRITICALCVSS 9.8EG 9.82023-03-12
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
- CVE-2023-1114CRITICALCVSS 9.8EG 9.82023-03-01
Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.100.
- CVE-2021-31577CRITICALCVSS 9.8EG 9.82023-02-06
In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not neede…
- CVE-2023-0556CRITICALCVSS 9.8EG 9.82023-01-27
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the…
- CVE-2022-41417CRITICALCVSS 9.8EG 9.82023-01-18
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.
- CVE-2021-45467CRITICALCVSS 9.8EG 9.82022-12-26
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00…
- CVE-2022-41326CRITICALCVSS 9.8EG 9.82022-11-22
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the…
- CVE-2022-38651CRITICALCVSS 9.8EG 9.82022-11-12
A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerabi…
- CVE-2022-41238CRITICALCVSS 9.8EG 9.82022-09-21
A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.
- CVE-2022-36642CRITICALCVSS 9.8EG 9.82022-09-02
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high pr…
- CVE-2022-1245CRITICALCVSS 9.8EG 9.82022-07-08
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target…
- CVE-2022-1574CRITICALCVSS 9.8EG 9.82022-06-27
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
- CVE-2022-0885CRITICALCVSS 9.8EG 9.82022-06-13
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
- CVE-2022-28993CRITICALCVSS 9.8EG 9.82022-05-20
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
- CVE-2022-22282CRITICALCVSS 9.8EG 9.82022-05-13
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.
- CVE-2022-29906CRITICALCVSS 9.8EG 9.82022-04-29
The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.
- CVE-2022-1020CRITICALCVSS 9.8EG 9.82022-04-18
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as…
- CVE-2022-24595CRITICALCVSS 9.8EG 9.82022-03-18
Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Control in usr/bin/afb-daemon. To exploit the vulnerability, an attacker should send a well-crafted HTTP (or WebSocket) req…
- CVE-2021-25032CRITICALCVSS 9.8EG 9.82022-01-10
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure…
- CVE-2021-27856CRITICALCVSS 9.8EG 9.82021-12-15
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatP…
- CVE-2021-36888CRITICALCVSS 9.8EG 9.82021-12-15
Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.
- CVE-2021-24915CRITICALCVSS 9.8EG 9.82021-11-29
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which c…
- CVE-2021-21694CRITICALCVSS 9.8EG 9.82021-11-04
FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
- CVE-2021-32172CRITICALCVSS 9.8EG 9.82021-10-07
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
- CVE-2021-33924CRITICALCVSS 9.8EG 9.82021-09-29
Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information.
- CVE-2021-37270CRITICALCVSS 9.8EG 9.82021-09-27
There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the background to obtain the b…
- CVE-2021-37535CRITICALCVSS 9.8EG 9.82021-09-14
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.
- CVE-2020-24672CRITICALCVSS 9.8EG 9.82021-09-08
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .
- CVE-2020-18753CRITICALCVSS 9.8EG 9.82021-08-13
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted packet.
- CVE-2021-35327CRITICALCVSS 9.8EG 9.82021-08-05
A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, then login with the default credentials via a crafted POST request.
- CVE-2020-36239CRITICALCVSS 9.8EG 9.82021-07-29
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version…
- CVE-2021-36124CRITICALCVSS 9.8EG 9.82021-07-13
An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerab…
- CVE-2021-27903CRITICALCVSS 9.8EG 9.82021-06-30
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administ…
- CVE-2021-31921CRITICALCVSS 9.8EG 9.82021-06-02
Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can access unexpected services in the cluster, bypassing authorization checks, when a gateway is configured with AUTO_PASSTHRO…
- CVE-2021-22891CRITICALCVSS 9.8EG 9.82021-05-27
A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.
- CVE-2021-27573CRITICALCVSS 9.8EG 9.82021-05-07
An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with no prior authorization or authentication.
- CVE-2021-21984CRITICALCVSS 9.8EG 9.82021-05-07
VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution …
- CVE-2021-1508CRITICALCVSS 9.8EG 9.82021-05-06
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privil…
- CVE-2021-1506CRITICALCVSS 9.8EG 9.82021-05-06
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privil…
- CVE-2021-1505CRITICALCVSS 9.8EG 9.82021-05-06
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privil…
- CVE-2021-28141CRITICALCVSS 9.8EG 9.82021-03-11
An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web.UI.WebResource.axd file. This may allow the attacker to gain unauthorized access to the s…
- CVE-2021-21978CRITICALCVSS 9.8EG 9.82021-03-03
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attack…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →