VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,117)

page 16 of 506
  • CVE-2025-20362MedKEVSep 25, 2025
    risk 0.61cvss 6.5epss 0.87

    Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload,…

  • CVE-2024-2882CriJun 27, 2024
    risk 0.61cvss —epss 0.01

    SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. This breach could potentially lead to unauthorized control, data manipulation, and access to sensitive information within the SCADA system.

  • CVE-2023-36348HigJun 23, 2023
    risk 0.61cvss 8.8epss 0.06

    POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename parameter.

  • CVE-2022-41271CriDec 13, 2022
    risk 0.61cvss 9.4epss 0.01

    An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized…

  • CVE-2020-13144HigMay 18, 2020
    risk 0.61cvss 8.8epss 0.11

    Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads…

  • CVE-2019-6538CriMar 25, 2019
    risk 0.61cvss 9.3epss 0.01

    The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D…

  • CVE-2026-12710CriAug 22, 2026
    risk 0.60cvss —epss 0.00

    A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.

  • CVE-2026-15958CriAug 4, 2026
    risk 0.60cvss 9.3epss 0.00

    The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary…

  • CVE-2026-48797CriJun 17, 2026
    risk 0.60cvss —epss 0.01

    Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration,…

  • CVE-2026-44125CriMay 8, 2026
    risk 0.60cvss —epss 0.01

    SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to access functionality that should require a valid session.

  • CVE-2026-5387CriApr 15, 2026
    risk 0.60cvss —epss 0.01

    The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simulator Instructor or Simulator Developer (Administrator) roles, resulting in privilege escalation with potential for modification of simulation parameters,…

  • CVE-2026-28515HigFeb 27, 2026
    risk 0.60cvss 8.8epss 0.02

    openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and container-install.php. The installer and upgrade handler expose LDAP configuration functionality without enforcing application role checks. Any authenticated user…

  • CVE-2015-10140HigJul 22, 2025
    risk 0.60cvss 8.8epss 0.01

    The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.

  • CVE-2025-2407CriMay 27, 2025
    risk 0.60cvss —epss 0.00

    Missing Authentication & Authorization in Web-API in Mobatime AMX MTAPI v6 on IIS allows adversaries to unrestricted access via the network. The vulnerability is fixed in Version 1.5.

  • CVE-2024-8074CriNov 12, 2024
    risk 0.60cvss —epss 0.00

    Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users. This issue affects Nomysem: before 13.10.2024.

  • CVE-2023-25573HigMar 9, 2023
    risk 0.60cvss 8.6epss 0.52

    metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the…

  • CVE-2022-0218HigFeb 4, 2022
    risk 0.60cvss 8.3epss 0.71

    The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file,…

  • CVE-2021-21246HigJan 15, 2021
    risk 0.60cvss 8.6epss 0.49

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the `/users/{id}` endpoint there are no security checks enforced so it is…

  • CVE-2020-1963CriJun 3, 2020
    risk 0.60cvss 9.1epss 0.05

    Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.

  • CVE-2017-5180HigFeb 9, 2017
    risk 0.60cvss 8.8epss 0.01

    Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the…