VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 2 of 463
  • CVE-2015-10143CriJul 25, 2025
    risk 0.67cvss 9.8epss 0.02

    The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the *_ajax_save_options() function in all versions up to 1.4.4 (exclusive). This makes it possible for unauthenticated…

  • CVE-2023-6875CriJan 11, 2024
    risk 0.67cvss 9.8epss 0.90

    The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all versions up to, and…

  • CVE-2020-14944CriJun 22, 2020
    risk 0.67cvss 9.8epss 0.06

    Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile,…

  • CVE-2017-6639CriJun 8, 2017
    risk 0.67cvss 9.8epss 0.35

    A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system. The…

  • CVE-2022-1020CriApr 18, 2022
    risk 0.66cvss 9.8epss 0.26

    The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback…

  • CVE-2022-23642HigFeb 18, 2022
    risk 0.66cvss 8.8epss 0.74

    Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the…

  • CVE-2018-10093HigMar 21, 2019
    risk 0.66cvss 8.8epss 0.68

    AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.

  • CVE-2026-65667CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.00

    Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-58275CriJul 24, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-0092CriJun 17, 2026
    risk 0.65cvss epss 0.00

    In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-33712CriMay 22, 2026
    risk 0.65cvss 10.0epss 0.00

    Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Request Forgery (SSRF) by supplying a custom typebot definition with server-side…

  • CVE-2026-2031CriMay 15, 2026
    risk 0.65cvss epss 0.01

    An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted…

  • CVE-2025-30416CriFeb 20, 2026
    risk 0.65cvss 10.0epss 0.00

    Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

  • CVE-2025-45854CriJun 3, 2025
    risk 0.65cvss 10.0epss 0.03

    /server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.

  • CVE-2025-26853CriMar 20, 2025
    risk 0.65cvss 10.0epss 0.00

    DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.

  • CVE-2025-22612CriJan 24, 2025
    risk 0.65cvss 10.0epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.374, the missing authorization allows an authenticated user to retrieve any existing private keys on a coolify instance in plain text. If the server…

  • CVE-2025-22609CriJan 24, 2025
    risk 0.65cvss 10.0epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to attach any existing private key on a coolify instance to his own server. If the server…

  • CVE-2024-52416CriNov 16, 2024
    risk 0.65cvss 10.0epss 0.00

    Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through <= 2.2.

  • CVE-2024-9234CriOct 11, 2024
    risk 0.65cvss 9.8epss 0.10

    The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API…

  • CVE-2024-6500CriAug 17, 2024
    risk 0.65cvss 10.0epss 0.01

    The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion of data due to a missing capability check on the 'parse_request' function in all versions up to, and including, 1.4.0 (for InPost for WooCommerce) as well as…