VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 90 of 464
  • CVE-2023-23988HigMay 17, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Joseph C Dolson My Tickets.This issue affects My Tickets: from n/a through 1.9.11.

  • CVE-2024-32724HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Woo product importer Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1.

  • CVE-2024-31270HigMay 8, 2024
    risk 0.49cvss 7.6epss 0.00

    Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.

  • CVE-2024-32810HigMay 3, 2024
    risk 0.49cvss 7.6epss 0.00

    Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: from n/a through 1.0.2.

  • CVE-2024-33594HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Leaky Paywall.This issue affects Leaky Paywall: from n/a through 4.20.8.

  • CVE-2024-33591HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Tips and Tricks HQ Easy Accept Payments.This issue affects Easy Accept Payments: from n/a through 4.9.10.

  • CVE-2024-33635HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.

  • CVE-2024-33597HigApr 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in ProFaceOff SSU.This issue affects SSU: from n/a through 1.5.0.

  • CVE-2023-44227HigApr 17, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a through 6.1.9.

  • CVE-2023-51672HigApr 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

  • CVE-2024-31343HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1.

  • CVE-2024-31358HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67.

  • CVE-2024-31297HigApr 10, 2024
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

  • CVE-2024-1934HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wps_local_compress::__construct' function in all versions up to, and including, 6.11.10. This makes it possible for…

  • CVE-2023-52541HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Authentication vulnerability in the API for app pre-loading. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-27911HigApr 5, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.

  • CVE-2024-30487HigMar 29, 2024
    risk 0.49cvss 7.6epss 0.00

    Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.

  • CVE-2024-2848HigMar 29, 2024
    risk 0.49cvss 7.5epss 0.01

    The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_footer_text_callback function in all versions up to, and including, 5.0.2. This makes it possible for unauthenticated attackers to inject arbitrary…

  • CVE-2023-49981HigMar 21, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

  • CVE-2023-49980HigMar 21, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.