CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,487)
page 232 of 475| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-4102 | Med | 0.35 | 5.4 | 0.00 | Jul 9, 2024 | The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above,… | ||
| CVE-2024-37172 | Med | 0.35 | 5.4 | 0.00 | Jul 9, 2024 | SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and availability but there is no impact on the integrity. | ||
| CVE-2024-37542 | Med | 0.35 | 5.4 | 0.00 | Jul 6, 2024 | Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3. | ||
| CVE-2024-36995 | Med | 0.35 | 5.4 | 0.00 | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could create experimental items. | ||
| CVE-2024-6375 | Med | 0.35 | 5.4 | 0.00 | Jul 1, 2024 | A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server… | ||
| CVE-2024-5710 | Med | 0.35 | 6.5 | 0.00 | Jun 27, 2024 | berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding… | ||
| CVE-2024-3627 | Med | 0.35 | 5.4 | 0.00 | Jun 20, 2024 | The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the AjaxFunctions.php file in all versions up to, and including, 1.1.7. This… | ||
| CVE-2023-38394 | Med | 0.35 | 5.4 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0. | ||
| CVE-2023-39310 | Med | 0.35 | 5.4 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1. | ||
| CVE-2023-36676 | Med | 0.35 | 5.4 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6. | ||
| CVE-2023-39990 | Med | 0.35 | 5.4 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3. | ||
| CVE-2023-35050 | Med | 0.35 | 5.4 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0. | ||
| CVE-2023-44151 | Med | 0.35 | 5.4 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in Brainstorm Force Pre-Publish Checklist.This issue affects Pre-Publish Checklist: from n/a through 1.1.1. | ||
| CVE-2023-44148 | Med | 0.35 | 5.4 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7. | ||
| CVE-2023-51497 | Med | 0.35 | 5.4 | 0.00 | Jun 14, 2024 | Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9. | ||
| CVE-2023-51516 | Med | 0.35 | 5.4 | 0.00 | Jun 14, 2024 | Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9. | ||
| CVE-2023-36695 | Med | 0.35 | 5.4 | 0.00 | Jun 14, 2024 | Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9. | ||
| CVE-2023-40672 | Med | 0.35 | 5.4 | 0.00 | Jun 12, 2024 | Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1. | ||
| CVE-2023-38395 | Med | 0.35 | 5.4 | 0.00 | Jun 12, 2024 | Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1. | ||
| CVE-2023-52177 | Med | 0.35 | 5.4 | 0.00 | Jun 12, 2024 | Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3. |
- risk 0.35cvss 5.4epss 0.00
The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above,…
- risk 0.35cvss 5.4epss 0.00
SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and availability but there is no impact on the integrity.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
- risk 0.35cvss 5.4epss 0.00
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could create experimental items.
- risk 0.35cvss 5.4epss 0.00
A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server…
- risk 0.35cvss 6.5epss 0.00
berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, updating, viewing, deleting, blocking, and unblocking any teams, as well as adding…
- risk 0.35cvss 5.4epss 0.00
The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the AjaxFunctions.php file in all versions up to, and including, 1.1.7. This…
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Brainstorm Force Spectra.This issue affects Spectra: from n/a through 2.6.6.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Brainstorm Force Pre-Publish Checklist.This issue affects Pre-Publish Checklist: from n/a through 1.1.1.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Maxime Schoeni Sublanguage.This issue affects Sublanguage: from n/a through 2.9.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Hardik Chavada Sticky Social Media Icons.This issue affects Sticky Social Media Icons: from n/a through 2.1.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Afzal Multani WP Clone Menu.This issue affects WP Clone Menu: from n/a through 1.0.1.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.