CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,344 vulnerabilities with CWE-862
CVE-2025-0935 MEDIUM
Media Library Folders <= 8.3.0 - Authenticated Plugin Settings Change via Missing Capability Check
CVSS 4.3
CVE-2025-24692 HIGH
Michael Revellin-Clerc Bulk Menu Edit <1.3 - RCE
CVSS 7.1
CVE-2025-24607 MEDIUM
IdeaPush <= 8.71 - Missing Authorization
CVSS 5.8
CVE-2025-23771 MEDIUM
Murali Push Notification <2.11 - RCE
CVSS 6.5
CVE-2025-23766 MEDIUM
OPSI Israel Domestic Shipments <2.6.6 - Info Disclosure
CVSS 6.5
CVE-2025-23534 MEDIUM
WPLingo <= 1.1.2 - Unauthenticated Arbitrary Content Deletion via Missing Authorization
CVSS 6.5
CVE-2025-22702 MEDIUM
EPC Photography <7.5.2 - Info Disclosure
CVSS 6.3
CVE-2025-22698 MEDIUM
Ability, Inc Accessibility Suite <4.16 - RCE
CVSS 6.3
CVE-2025-1214 MEDIUM
PiHome maxair - Missing Authorization in Role-Based Access Control via /user_accounts.php?uid
CVSS 6.3
CVE-2025-26378 HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Password Reset via Crafted HTTP Requests
CVSS 8.8
CVE-2025-26377 HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated User Removal via Crafted HTTP Requests
CVSS 8.1
CVE-2025-26376 MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated User Data Modification via Crafted HTTP Requests
CVSS 6.5
CVE-2025-26375 HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Privilege Escalation via User Creation
CVSS 8.8
CVE-2025-26374 MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated User Enumeration via Users Endpoint
CVSS 6.5
CVE-2025-26373 MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated User Enumeration via User Endpoint
CVSS 6.5
CVE-2025-26372 HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated User Removal from Groups via Crafted HTTP Requests
CVSS 7.1
CVE-2025-26371 HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Missing Authorization in User-Groups Routes
CVSS 8.8
CVE-2025-26370 HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Privilege Removal via User Groups Route
CVSS 7.1
CVE-2025-26369 HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Privilege Escalation via User Group Route
CVSS 8.8
CVE-2025-26368 HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated User Group Removal via Crafted HTTP Requests
CVSS 8.1
CVE-2025-26367 MEDIUM
Q-Free MaxTime <= 2.11.0 - Authenticated Arbitrary User Group Creation via HTTP Request
CVSS 4.3
CVE-2025-0526 MEDIUM
Octopus Server 2022.4.791-2024.3.13097 - Unauthenticated Arbitrary File Write via API Endpoint
CVSS 5.4
CVE-2025-25241 MEDIUM
SAP Fiori Apps Reference Library (My Overtime Requests) >=GBX01HR5 605 - Missing Authorization
CVSS 5.4
CVE-2025-23190 MEDIUM
SAP NetWeaver and ABAP Platform ST-PI - Missing Authorization Check
CVSS 4.3
CVE-2025-23189 MEDIUM
SAP NetWeaver and ABAP Platform (SDCCN) - Authenticated Missing Authorization in SDCCN Transaction
CVSS 4.3
Details
Vulnerabilities 8,344
Exploit Likelihood High