VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 402 of 464
  • CVE-2024-30512LowJun 9, 2024
    risk 0.24cvss 3.7epss 0.00

    Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.

  • CVE-2023-27437LowJun 3, 2024
    risk 0.24cvss 3.7epss 0.00

    Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.

  • CVE-2023-23985LowApr 24, 2024
    risk 0.24cvss 3.7epss 0.00

    Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4.

  • CVE-2020-9009LowApr 11, 2023
    risk 0.24cvss 3.7epss 0.01

    The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely unchecked. The attacker must guess an order number.

  • CVE-2019-6121LowNov 6, 2019
    risk 0.24cvss 3.7epss 0.01

    An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments, unclaimed Balance, Old Balance (at the time of December 2017 breach) , Projected payout, Mining…

  • CVE-2019-9171LowApr 17, 2019
    risk 0.24cvss 3.7epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).

  • CVE-2018-2419LowMay 9, 2018
    risk 0.24cvss 3.7epss 0.01

    SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2017-17433LowDec 6, 2017
    risk 0.24cvss 3.7epss 0.02

    The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended…

  • CVE-2025-12704LowMar 11, 2026
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization…

  • CVE-2026-24310LowMar 10, 2026
    risk 0.23cvss 3.5epss 0.00

    Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute specific ABAP function module and read the sensitive information from database catalog of the ABAP system. This vulnerability has low impact on the…

  • CVE-2025-10583LowDec 12, 2025
    risk 0.23cvss 3.5epss 0.00

    The WP Fastest Cache Premium plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.7.4 via the 'get_server_time_ajax_request' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and…

  • CVE-2025-58816LowSep 5, 2025
    risk 0.23cvss 3.5epss 0.00

    Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor ecommerce-product-carousel-slider-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Carousel Slider for Elementor: from n/a…

  • CVE-2025-42955LowAug 12, 2025
    risk 0.23cvss 3.5epss 0.00

    Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges could send a crafted request to the endpoint responsible for testing LDAP connections. A successful exploit could lead to reduced performance, hence a low-impact…

  • CVE-2023-24375LowDec 9, 2024
    risk 0.23cvss 3.5epss 0.00

    Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Social Login and Register (Discord, Google, Twitter,…

  • CVE-2024-47587LowNov 12, 2024
    risk 0.23cvss 3.5epss 0.00

    Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges causing low impact to confidentiality to the application.

  • CVE-2024-33000LowMay 14, 2024
    risk 0.23cvss 3.5epss 0.00

    SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.

  • CVE-2023-22836LowJan 29, 2024
    risk 0.23cvss 3.5epss 0.00

    In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed value may be visible to the rest of the stack’s tenants.

  • CVE-2023-4700LowNov 6, 2023
    risk 0.23cvss 3.5epss 0.00

    An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.

  • CVE-2022-3501LowOct 17, 2022
    risk 0.23cvss 3.5epss 0.00

    Article template contents with sensitive data could be accessed from agents without permissions.

  • CVE-2022-20330LowAug 12, 2022
    risk 0.23cvss 3.5epss 0.00

    In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…