VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,439)

page 305 of 472
  • CVE-2026-40592MedApr 21, 2026
    risk 0.31cvss 5.9epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify that the current user created the…

  • CVE-2026-40265MedApr 17, 2026
    risk 0.31cvss 5.9epss 0.00

    Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID} is registered without authentication middleware, and the backend query does not verify ownership or book visibility. An…

  • CVE-2026-30850MedMar 7, 2026
    risk 0.31cvss 5.9epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.9 and 9.5.0-alpha.9, the file metadata endpoint (GET /files/:appId/metadata/:filename) does not enforce beforeFind / afterFind file triggers. When these…

  • CVE-2025-68947MedJan 13, 2026
    risk 0.31cvss 4.7epss 0.00

    NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

  • CVE-2025-31606MedMar 31, 2025
    risk 0.31cvss 4.8epss 0.00

    Missing Authorization vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Blog Designer: from n/a through <= 1.0.0.

  • CVE-2025-27294MedFeb 24, 2025
    risk 0.31cvss 4.8epss 0.00

    Missing Authorization vulnerability in platcom WP-Asambleas wp-asambleas allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Asambleas: from n/a through <= 2.85.0.

  • CVE-2025-22677MedFeb 3, 2025
    risk 0.31cvss 4.8epss 0.00

    Missing Authorization vulnerability in UIUX Lab Uix Shortcodes uix-shortcodes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uix Shortcodes: from n/a through <= 2.0.3.

  • CVE-2024-12955MedDec 26, 2024
    risk 0.31cvss 4.3epss 0.01

    A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as problematic. This vulnerability affects unknown code of the file /logout.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The…

  • CVE-2023-23895MedDec 9, 2024
    risk 0.31cvss 4.7epss 0.01

    Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through 1.1.82.

  • CVE-2024-53825MedDec 6, 2024
    risk 0.31cvss 4.7epss 0.00

    Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filebird: from n/a through <= 6.3.2.

  • CVE-2024-52529MedNov 25, 2024
    risk 0.31cvss 5.8epss 0.01

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a Layer 3 destination and a port range `AND` 2. A Layer 7 allow policy that selects a specific port within the…

  • CVE-2024-6591MedJul 27, 2024
    risk 0.31cvss 5.8epss 0.00

    The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' and 'resend_auction_email_callback' functions in all versions up to, and including, 4.2.7.…

  • CVE-2024-32957MedApr 26, 2024
    risk 0.31cvss 4.7epss 0.00

    Missing Authorization vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: from n/a through 1.5.38.

  • CVE-2024-27953MedMar 13, 2024
    risk 0.31cvss 4.7epss 0.00

    Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affects Cryptocurrency Widgets – Price Ticker & Coins List: from n/a through 2.6.8.

  • CVE-2024-27906MedFeb 29, 2024
    risk 0.31cvss 5.9epss 0.00

    Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import errors of DAGs they do not have permission to view through the API and the UI. Users of Apache Airflow are recommended to upgrade to version 2.8.2 or newer to…

  • CVE-2023-40530MedAug 25, 2023
    risk 0.31cvss 4.7epss 0.01

    Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier allows an attacker to lead a user to access an arbitrary website via another application installed on the user's device.

  • CVE-2022-2846MedAug 16, 2022
    risk 0.31cvss 4.3epss 0.03

    The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create…

  • CVE-2022-1384MedApr 19, 2022
    risk 0.31cvss 4.7epss 0.01

    Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Marketplace, which allows an authenticated and an authorized user to install and exploit an old plugin version from the Marketplace which might have known…

  • CVE-2018-1000015MedJan 23, 2018
    risk 0.31cvss 4.8epss 0.01

    On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline:…

  • CVE-2026-64676MedAug 7, 2026
    risk 0.30cvss 5.7epss 0.00

    Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypass in confidential-guest memory management. In Confidential Containers (CoCo)…