VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,262)

page 38 of 464
  • CVE-2024-38190HigOct 15, 2024
    risk 0.56cvss 8.6epss 0.01

    Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.

  • CVE-2023-52233HigJun 11, 2024
    risk 0.56cvss 8.6epss 0.00

    Missing Authorization vulnerability in Post SMTP Post SMTP Mailer/Email Log.This issue affects Post SMTP Mailer/Email Log: from n/a through 2.8.6.

  • CVE-2024-34378HigMay 6, 2024
    risk 0.56cvss 8.6epss 0.00

    Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7.

  • CVE-2024-25911HigApr 16, 2024
    risk 0.56cvss 8.6epss 0.01

    Missing Authorization vulnerability in Skymoon Labs MoveTo.This issue affects MoveTo: from n/a through 6.2.

  • CVE-2023-6600HigJan 3, 2024
    risk 0.56cvss 8.6epss 0.00

    The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init in all versions up to,…

  • CVE-2020-23793HigAug 22, 2023
    risk 0.56cvss 8.6epss 0.01

    An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.

  • CVE-2022-46850HigJun 19, 2023
    risk 0.56cvss 8.6epss 0.01

    Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin <= 0.1.3 versions.

  • CVE-2020-36712HigJun 7, 2023
    risk 0.56cvss 8.6epss 0.01

    The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for…

  • CVE-2023-26035HigFeb 25, 2023
    risk 0.56cvss 7.2epss 0.80

    ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions…

  • CVE-2023-25014HigFeb 2, 2023
    risk 0.56cvss 8.6epss 0.01

    An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users.

  • CVE-2021-44793HigJan 27, 2022
    risk 0.56cvss 8.6epss 0.01

    Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a…

  • CVE-2021-41238HigNov 2, 2021
    risk 0.56cvss 8.6epss 0.01

    Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows Service or separate process required. Dashboard UI in Hangfire.Core uses authorization filters to protect it from showing sensitive data to unauthorized users.…

  • CVE-2021-37976MedKEVOct 8, 2021
    risk 0.56cvss 6.5epss 0.20

    Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2021-30657MedKEVSep 8, 2021
    risk 0.56cvss 5.5epss 0.69

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

  • CVE-2017-7914HigJun 14, 2017
    risk 0.56cvss 8.6epss 0.07

    A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.00-20130325, 7.00-20130619, 7.00-20140128, 7.00-20140310, 7.00-20140429,…

  • CVE-2026-73843CriAug 13, 2026
    risk 0.55cvss 9.6epss 0.00

    OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to…

  • CVE-2026-18947HigAug 10, 2026
    risk 0.55cvss 8.5epss 0.00

    A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an…

  • CVE-2026-72737CriAug 10, 2026
    risk 0.55cvss 9.6epss 0.00

    Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId and use the referenced destination without…

  • CVE-2026-47416CriJul 21, 2026
    risk 0.55cvss 9.6epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`,…

  • CVE-2026-47413CriJul 21, 2026
    risk 0.55cvss 9.6epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `require_workspace_member(workspace_id)…