VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 182 of 475
  • CVE-2025-39580MedApr 17, 2025
    risk 0.38cvss 5.8epss 0.00

    Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dashi: from n/a through <= 3.1.8.

  • CVE-2025-31876MedApr 3, 2025
    risk 0.38cvss 5.8epss 0.00

    Missing Authorization vulnerability in gunnarpayday Payday payday allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payday: from n/a through <= 3.3.18.

  • CVE-2025-24607MedFeb 14, 2025
    risk 0.38cvss 5.8epss 0.00

    Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a through <= 8.71.

  • CVE-2025-22720MedJan 31, 2025
    risk 0.38cvss 5.8epss 0.00

    Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.2.1.

  • CVE-2025-22385MedJan 4, 2025
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium-severity issue allows the mass creation of accounts. This could affect database storage; also,…

  • CVE-2024-49596MedNov 26, 2024
    risk 0.38cvss 5.9epss 0.00

    Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion

  • CVE-2024-43919MedNov 1, 2024
    risk 0.38cvss 5.3epss 0.44

    Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.

  • CVE-2024-43274MedNov 1, 2024
    risk 0.38cvss 5.8epss 0.00

    Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.6.

  • CVE-2024-1380MedMar 13, 2024
    risk 0.38cvss 5.3epss 0.50

    The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssi_export_log_check() function in all versions up to, and including, 4.22.0 (Free) and 2.25.0 (Premium). This makes it possible…

  • CVE-2024-2107MedMar 12, 2024
    risk 0.38cvss 5.8epss 0.00

    The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.3 via generated source. This makes it possible for unauthenticated attackers to extract sensitive data including contents of password-protected or…

  • CVE-2023-5612MedJan 26, 2024
    risk 0.38cvss 5.3epss 0.05

    An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

  • CVE-2023-5054MedSep 19, 2023
    risk 0.38cvss 5.8epss 0.01

    The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for…

  • CVE-2021-4369MedJun 7, 2023
    risk 0.38cvss 5.8epss 0.01

    The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the…

  • CVE-2021-4351MedJun 7, 2023
    risk 0.38cvss 5.8epss 0.01

    The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This…

  • CVE-2022-39861MedOct 7, 2022
    risk 0.38cvss 5.9epss 0.00

    Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege.

  • CVE-2022-2552MedAug 22, 2022
    risk 0.38cvss 5.3epss 0.11

    The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and full file system path to the site.

  • CVE-2021-40327MedJan 13, 2022
    risk 0.38cvss 5.9epss 0.01

    Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) based solely on knowledge of its key ID. For example, there is no authorization check associated with the relationship between a…

  • CVE-2020-4816MedJan 27, 2021
    risk 0.38cvss 5.9epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.4.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…

  • CVE-2020-4841MedDec 21, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM Security Secret Server 10.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…

  • CVE-2020-4783MedNov 23, 2020
    risk 0.38cvss 5.9epss 0.01

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the…