CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,267)
page 48 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-5905 | Hig | 0.53 | 8.1 | 0.01 | Jan 15, 2024 | The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished… | ||
| CVE-2023-48222 | Hig | 0.53 | 8.1 | 0.00 | Nov 16, 2023 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Process Automation products could allow authenticated users to access the URL path, which would allow… | ||
| CVE-2023-6020 | Hig | 0.53 | 7.5 | 0.15 | Nov 16, 2023 | LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication. | ||
| CVE-2023-43885 | Hig | 0.53 | 8.1 | 0.01 | Nov 7, 2023 | Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device. | ||
| CVE-2022-3007 | Hig | 0.53 | 8.1 | 0.00 | Oct 31, 2023 | The vulnerability exists in Syska SW100 Smartwatch due to an improper implementation and/or configuration of Nordic Device Firmware Update (DFU) which is used for performing Over-The-Air (OTA) firmware updates on the Bluetooth Low Energy (BLE) devices. An unauthenticated… | ||
| CVE-2023-30969 | Hig | 0.53 | 8.2 | 0.00 | Oct 26, 2023 | The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints. | ||
| CVE-2023-4606 | Hig | 0.53 | 8.1 | 0.00 | Oct 25, 2023 | An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. | ||
| CVE-2023-43652 | Hig | 0.53 | 8.2 | 0.01 | Sep 27, 2023 | JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a password or the corresponding SSH private key. An SSH public key should be considered public knowledge… | ||
| CVE-2023-39438 | Hig | 0.53 | 8.1 | 0.00 | Aug 15, 2023 | A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons… | ||
| CVE-2023-37862 | Hig | 0.53 | 8.2 | 0.01 | Aug 9, 2023 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service. | ||
| CVE-2023-34463 | Hig | 0.53 | 8.1 | 0.01 | Jun 26, 2023 | DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade.… | ||
| CVE-2021-4383 | Hig | 0.53 | 8.1 | 0.01 | Jun 7, 2023 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as… | ||
| CVE-2023-2545 | Hig | 0.53 | 8.1 | 0.01 | May 31, 2023 | The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with… | ||
| CVE-2023-25552 | Hig | 0.53 | 8.1 | 0.01 | Apr 18, 2023 | A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products:… | ||
| CVE-2023-27701 | Hig | 0.53 | 8.1 | 0.01 | Mar 28, 2023 | MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html. | ||
| CVE-2023-1262 | Hig | 0.53 | 8.2 | 0.00 | Mar 21, 2023 | Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network. | ||
| CVE-2023-1261 | Hig | 0.53 | 8.2 | 0.00 | Mar 21, 2023 | Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network. | ||
| CVE-2022-45636 | Hig | 0.53 | 8.1 | 0.01 | Mar 21, 2023 | An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests. | ||
| CVE-2022-3999 | Hig | 0.53 | 8.1 | 0.00 | Dec 12, 2022 | The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable. | ||
| CVE-2022-26423 | Hig | 0.53 | 8.2 | 0.01 | Oct 21, 2022 | Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials. |
- risk 0.53cvss 8.1epss 0.01
The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished…
- risk 0.53cvss 8.1epss 0.00
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In affected versions access to two URLs used in both Rundeck Open Source and Process Automation products could allow authenticated users to access the URL path, which would allow…
- risk 0.53cvss 7.5epss 0.15
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
- risk 0.53cvss 8.1epss 0.01
Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.
- risk 0.53cvss 8.1epss 0.00
The vulnerability exists in Syska SW100 Smartwatch due to an improper implementation and/or configuration of Nordic Device Firmware Update (DFU) which is used for performing Over-The-Air (OTA) firmware updates on the Bluetooth Low Energy (BLE) devices. An unauthenticated…
- risk 0.53cvss 8.2epss 0.00
The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.
- risk 0.53cvss 8.1epss 0.00
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
- risk 0.53cvss 8.2epss 0.01
JumpServer is an open source bastion host. As an unauthenticated user, it is possible to authenticate to the core API with a username and an SSH public key without needing a password or the corresponding SSH private key. An SSH public key should be considered public knowledge…
- risk 0.53cvss 8.1epss 0.00
A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons…
- risk 0.53cvss 8.2epss 0.01
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.
- risk 0.53cvss 8.1epss 0.01
DataEase is an open source data visualization analysis tool to analyze data and gain insight into business trends. In affected versions Unauthorized users can delete an application erroneously. This vulnerability has been fixed in version 1.18.8. Users are advised to upgrade.…
- risk 0.53cvss 8.1epss 0.01
The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and including, 5.5. This is due to missing capability checks in the plugin's page-editing functionality. This makes it possible for low-authenticated attackers, such as…
- risk 0.53cvss 8.1epss 0.01
The Feather Login Page plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getListOfUsers' function in versions starting from 1.0.7 up to, and including, 1.1.1. This makes it possible for authenticated attackers, with…
- risk 0.53cvss 8.1epss 0.01
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products:…
- risk 0.53cvss 8.1epss 0.01
MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html.
- risk 0.53cvss 8.2epss 0.00
Missing MAC layer security in Silicon Labs Wi-SUN Linux Border Router v1.5.2 and earlier allows malicious node to route malicious messages through network.
- risk 0.53cvss 8.2epss 0.00
Missing MAC layer security in Silicon Labs Wi-SUN SDK v1.5.0 and earlier allows malicious node to route malicious messages through network.
- risk 0.53cvss 8.1epss 0.01
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.
- risk 0.53cvss 8.1epss 0.00
The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which could allow any authenticated users, such as subscriber to delete arbitrary options from the blog, which could make the blog unavailable.
- risk 0.53cvss 8.2epss 0.01
Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.