VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 7 of 463
  • CVE-2024-13513CriFeb 15, 2025
    risk 0.64cvss 9.8epss 0.01

    The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data…

  • CVE-2024-12822CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.01

    The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the add_capto_img() function in all versions up to, and including, 3.11.0. This makes it possible for…

  • CVE-2025-22611CriJan 24, 2025
    risk 0.64cvss 9.9epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to escalate his or any other team members privileges to any role, including the owner…

  • CVE-2024-56066CriDec 31, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in inspry Agency Toolkit agency-toolkit allows Privilege Escalation.This issue affects Agency Toolkit: from n/a through <= 1.0.23.

  • CVE-2024-11281CriDec 25, 2024
    risk 0.64cvss 9.8epss 0.02

    The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to insufficient validation on the 'logged_in_user_id' value when option values are empty and the ability for attackers to change the…

  • CVE-2024-54239CriDec 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through <= 4.0.18.

  • CVE-2024-45493CriDec 10, 2024
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to be restricted to login locally on the device. However, an attacker can bypass the check for this, which might allow…

  • CVE-2024-43222CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in SeventhQueen Sweet Date sweetdate allows Privilege Escalation.This issue affects Sweet Date: from n/a through <= 3.7.3.

  • CVE-2023-32117CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.07

    Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

  • CVE-2024-12155CriDec 6, 2024
    risk 0.64cvss 9.8epss 0.01

    The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the settings_import() function in all versions up to, and including, 2.0.02. This makes it possible for…

  • CVE-2024-0138CriNov 23, 2024
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

  • CVE-2024-52382CriNov 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue affects Matix Popup Builder: from n/a through <= 1.0.0.

  • CVE-2024-10575CriNov 13, 2024
    risk 0.64cvss 9.8epss 0.01

    CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.

  • CVE-2024-10589CriNov 9, 2024
    risk 0.64cvss 9.8epss 0.00

    The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the import_settings() function in all versions up to, and including, 3.1.1. This makes it…

  • CVE-2024-10586CriNov 9, 2024
    risk 0.64cvss 9.8epss 0.02

    The Debug Tool plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check on the dbt_pull_image() function and missing file type validation in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to to…

  • CVE-2024-48073CriNov 8, 2024
    risk 0.64cvss 9.8epss 0.01

    sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is responsible for updating the software in the HT3300 device, is given the execution mode of sudo NOPASSWD. This program is vulnerable to a command injection…

  • CVE-2024-50490CriOct 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through <= 1.0.2.

  • CVE-2024-50476CriOct 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.

  • CVE-2024-50475CriOct 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a through <= 1.0.

  • CVE-2024-48538CriOct 24, 2024
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.