VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 171 of 475
  • CVE-2025-15390MedDec 31, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and…

  • CVE-2025-64192MedDec 18, 2025
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in 8theme XStore xstore allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects XStore: from n/a through < 9.6.

  • CVE-2025-0836MedDec 16, 2025
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management Server to have full read/write access to MIP Webhooks API.

  • CVE-2025-2848MedDec 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.

  • CVE-2025-36361MedOct 24, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization.

  • CVE-2025-53236MedOct 22, 2025
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in AndonDesign UDesign Core u-design-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UDesign Core: from n/a through <= 4.14.0.

  • CVE-2025-49377MedOct 22, 2025
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hydra Booking: from n/a through <= 1.1.9.

  • CVE-2025-11438MedOct 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. Such manipulation leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed…

  • CVE-2025-8807MedAug 10, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tianti-module-admin/user/ajax/save. The manipulation leads to missing authorization. The attack can be initiated remotely. The…

  • CVE-2025-47565MedJul 4, 2025
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventON: from n/a through <= 4.9.9.

  • CVE-2025-5692MedJul 2, 2025
    risk 0.41cvss 6.3epss 0.00

    The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ~/includes/LB_admin_ajax.php file in all versions up to, and including, 3.1. This makes it possible for authenticated…

  • CVE-2025-43009MedMay 13, 2025
    risk 0.41cvss 6.3epss 0.00

    SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application.

  • CVE-2025-43007MedMay 13, 2025
    risk 0.41cvss 6.3epss 0.00

    SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on confidentiality, integrity and availability of the application.

  • CVE-2025-31841MedApr 3, 2025
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Frank P. Walentynowicz FPW Category Thumbnails fpw-category-thumbnails allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FPW Category Thumbnails: from n/a through <= 1.9.5.

  • CVE-2025-23440MedMar 3, 2025
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in radicaldesigns radSLIDE radslide allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects radSLIDE: from n/a through <= 2.1.

  • CVE-2025-22702MedFeb 14, 2025
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photography: from n/a through <= 7.7.2.

  • CVE-2025-22698MedFeb 14, 2025
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Suite: from n/a through <= 4.18.

  • CVE-2025-1214MedFeb 12, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in pihome-shc PiHome 2.0. This affects an unknown part of the file /user_accounts.php?uid of the component Role-Based Access Control. The manipulation leads to missing authorization. It is possible to initiate the attack…

  • CVE-2025-0939MedFeb 1, 2025
    risk 0.41cvss 6.3epss 0.00

    The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and…

  • CVE-2025-0067MedJan 14, 2025
    risk 0.41cvss 6.3epss 0.00

    Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low…