CWE-862— Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
10,777 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 8 of 216
- CVE-2021-21978CRITICALCVSS 9.8EG 9.82021-03-03
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attack…
- CVE-2020-35219CRITICALCVSS 9.8EG 9.82021-01-04
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_username=admin&uiView…
- CVE-2020-28215CRITICALCVSS 9.8EG 9.82020-12-11
A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control…
- CVE-2020-29006CRITICALCVSS 9.8EG 9.82020-11-24
MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.
- CVE-2020-7472CRITICALCVSS 9.8EG 9.82020-11-12
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a co…
- CVE-2020-28036CRITICALCVSS 9.8EG 9.82020-11-02
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
- CVE-2020-27998CRITICALCVSS 9.8EG 9.82020-10-29
An issue was discovered in FastReport before 2020.4.0. It lacks a ScriptSecurity feature and therefore may mishandle (for example) GetType, typeof, TypeOf, DllImport, LoadLibrary, and GetProcAddress.
- CVE-2020-7124CRITICALCVSS 9.8EG 9.82020-10-26
A remote unauthorized access vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
- CVE-2020-4499CRITICALCVSS 9.8EG 9.82020-10-15
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 could allow an unauthorized public Oauth client to bypass some or all of the authentication checks and gain access to applications. IBM X-Force ID: 182216.
- CVE-2020-11856CRITICALCVSS 9.8EG 9.82020-09-22
Arbitrary code execution vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to execute arbitrary code on affected installations of OBR.
- CVE-2020-25283CRITICALCVSS 9.8EG 9.82020-09-11
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. BT manager allows attackers to bypass intended access restrictions on a certain mode. The LG ID is LVE-SMP-200021 (September 2020).
- CVE-2020-25282CRITICALCVSS 9.8EG 9.82020-09-11
An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-2…
- CVE-2020-14001CRITICALCVSS 9.8EG 9.82020-07-17
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string th…
- CVE-2020-5368CRITICALCVSS 9.8EG 9.82020-07-06
Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.
- CVE-2020-14944CRITICALCVSS 9.8EG 9.82020-06-22
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exp…
- CVE-2018-21251CRITICALCVSS 9.8EG 9.82020-06-19
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.
- CVE-2019-18666CRITICALCVSS 9.8EG 9.82020-05-15
An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnerability, the impact depends on the firmwa…
- CVE-2020-10620CRITICALCVSS 9.8EG 9.82020-05-14
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.
- CVE-2020-7133CRITICALCVSS 9.8EG 9.82020-04-24
A unauthorized remote access vulnerability was discovered in HPE IOT + GCP version(s): 1.4.0, 1.4.1, 1.4.2, 1.2.4.2.
- CVE-2020-6823CRITICALCVSS 9.8EG 9.82020-04-24
A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. Th…
- CVE-2020-11967CRITICALCVSS 9.8EG 9.82020-04-21
In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, a…
- CVE-2018-21042CRITICALCVSS 9.8EG 9.82020-04-08
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code execution. The Samsung ID is SVE-2018-13299 (December 2018).
- CVE-2020-11514CRITICALCVSS 9.8EG 9.82020-04-07
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured …
- CVE-2016-11036CRITICALCVSS 9.8EG 9.82020-04-07
An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).
- CVE-2019-12498CRITICALCVSS 9.8EG 9.82020-03-20
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
- CVE-2020-10257CRITICALCVSS 9.8EG 9.82020-03-10
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_a…
- CVE-2020-8772CRITICALCVSS 9.8EG 9.82020-02-06
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.
- CVE-2019-19899CRITICALCVSS 9.8EG 9.82019-12-19
Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Modu…
- CVE-2019-15932CRITICALCVSS 9.8EG 9.82019-12-12
Intesync Solismed 3.3sp has Incorrect Access Control.
- CVE-2019-13547CRITICALCVSS 9.8EG 9.82019-10-31
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.
- CVE-2019-16124CRITICALCVSS 9.8EG 9.82019-09-09
In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.
- CVE-2019-14544CRITICALCVSS 9.8EG 9.82019-08-02
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
- CVE-2019-1010152CRITICALCVSS 9.8EG 9.82019-07-23
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80.
- CVE-2019-1010150CRITICALCVSS 9.8EG 9.82019-07-23
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php.
- CVE-2019-1010149CRITICALCVSS 9.8EG 9.82019-07-23
zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.
- CVE-2019-6580CRITICALCVSS 9.8EG 9.82019-06-12
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Sive…
- CVE-2019-10648CRITICALCVSS 9.8EG 9.82019-03-30
Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of a .openStream call within java.net.URL.
- CVE-2018-4059CRITICALCVSS 9.8EG 9.82019-03-21
An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can pr…
- CVE-2019-9002CRITICALCVSS 9.8EG 9.82019-02-22
An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original d…
- CVE-2018-18996CRITICALCVSS 9.8EG 9.82019-02-05
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server.
- CVE-2019-5886CRITICALCVSS 9.8EG 9.82019-01-10
An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lock file in the Add method, which allows an attacker to reinstall the database. The attacker can write arbitrary code to…
- CVE-2018-16591CRITICALCVSS 9.8EG 9.82018-09-10
FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_chan…
- CVE-2018-11541CRITICALCVSS 9.8EG 9.82018-07-09
A root privilege escalation vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows unauthorised access to privileged content via an unspecified vector. It affects the 1000 and 2000 devices 6.0.x up to Build 446,…
- CVE-2018-8755CRITICALCVSS 9.8EG 9.82018-06-25
NuCom WR644GACV devices before STA006 allow an attacker to download the configuration file without credentials. By downloading this file, an attacker can access the admin password, WPA key, and any config information of the device.
- CVE-2018-10251CRITICALCVSS 9.8EG 9.82018-05-04
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker t…
- CVE-2018-1217CRITICALCVSS 9.8EG 9.82018-04-09
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remot…
- CVE-2018-0015CRITICALCVSS 9.8EG 9.82018-02-22
A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a hos…
- CVE-2018-6000CRITICALCVSS 9.8EG 9.82018-01-22
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin passw…
- CVE-2018-5377CRITICALCVSS 9.8EG 9.82018-01-12
Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.
- CVE-2017-12582CRITICALCVSS 9.8EG 9.82017-08-18
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can a…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →