CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 89 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36516 | Hig | 0.49 | 7.6 | 0.01 | Jun 19, 2024 | Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3. | ||
| CVE-2023-38386 | Hig | 0.49 | 7.6 | 0.01 | Jun 19, 2024 | Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25. | ||
| CVE-2023-35049 | Hig | 0.49 | 7.5 | 0.01 | Jun 19, 2024 | Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0. | ||
| CVE-2023-47770 | Hig | 0.49 | 7.6 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1. | ||
| CVE-2023-45658 | Hig | 0.49 | 7.6 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in POSIMYTH Nexter.This issue affects Nexter: from n/a through 2.0.3. | ||
| CVE-2023-48759 | Hig | 0.49 | 7.5 | 0.00 | Jun 19, 2024 | Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13. | ||
| CVE-2023-48280 | Hig | 0.49 | 7.5 | 0.00 | Jun 12, 2024 | Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1. | ||
| CVE-2024-24703 | Hig | 0.49 | 8.6 | 0.00 | Jun 11, 2024 | Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.0.25. | ||
| CVE-2024-34800 | Hig | 0.49 | 7.6 | 0.00 | Jun 10, 2024 | Missing Authorization vulnerability in Crafthemes Crafthemes Demo Import crafthemes-demo-import allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crafthemes Demo Import: from n/a through <= 3.3. | ||
| CVE-2024-31283 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.2. | ||
| CVE-2024-32715 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1. | ||
| CVE-2024-32798 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.8.0. | ||
| CVE-2024-32777 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint.This issue affects BizPrint: from n/a through 4.3.39. | ||
| CVE-2024-33563 | Hig | 0.49 | 7.6 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8. | ||
| CVE-2024-33561 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8. | ||
| CVE-2024-33543 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06. | ||
| CVE-2024-31243 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2024 | Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. | ||
| CVE-2024-5130 | Hig | 0.49 | 7.5 | 0.00 | Jun 6, 2024 | An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due to the lack of proper authorization checks in the dataset deletion endpoint. Specifically,… | ||
| CVE-2024-1662 | Hig | 0.49 | 7.5 | 0.00 | Jun 5, 2024 | Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint Stock Company PowerBank Application allows Retrieve Embedded Sensitive Data. This issue affects PowerBank Application: before 2.02. | ||
| CVE-2024-35672 | Hig | 0.49 | 7.5 | 0.00 | Jun 4, 2024 | Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19. |
- risk 0.49cvss 7.6epss 0.01
Missing Authorization vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.3.
- risk 0.49cvss 7.6epss 0.01
Missing Authorization vulnerability in Saturday Drive Ninja Forms.This issue affects Ninja Forms: from n/a through 3.6.25.
- risk 0.49cvss 7.5epss 0.01
Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0.
- risk 0.49cvss 7.6epss 0.00
Missing Authorization vulnerability in Muffin Group Betheme.This issue affects Betheme: from n/a through 27.1.1.
- risk 0.49cvss 7.6epss 0.00
Missing Authorization vulnerability in POSIMYTH Nexter.This issue affects Nexter: from n/a through 2.0.3.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1.
- risk 0.49cvss 8.6epss 0.00
Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4.0.25.
- risk 0.49cvss 7.6epss 0.00
Missing Authorization vulnerability in Crafthemes Crafthemes Demo Import crafthemes-demo-import allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crafthemes Demo Import: from n/a through <= 3.3.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.2.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import.This issue affects Olive One Click Demo Import: from n/a through 1.1.1.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.8.0.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint.This issue affects BizPrint: from n/a through 4.3.39.
- risk 0.49cvss 7.6epss 0.00
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in 8theme XStore.This issue affects XStore: from n/a through 9.3.8.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
- risk 0.49cvss 7.5epss 0.00
An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due to the lack of proper authorization checks in the dataset deletion endpoint. Specifically,…
- risk 0.49cvss 7.5epss 0.00
Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint Stock Company PowerBank Application allows Retrieve Embedded Sensitive Data. This issue affects PowerBank Application: before 2.02.
- risk 0.49cvss 7.5epss 0.00
Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19.