The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,345 vulnerabilities with CWE-862
CVE-2024-32589
HIGH
UkrSolution Barcode Scanner <1.5.3 - Info Disclosure
CVSS 7.1
CVE-2024-8860
MEDIUM
Tourfic < 2.14.5 - Authenticated Missing Authorization in Order and Visitor Management Functions
CVSS 4.3
CVE-2024-53298
CRITICAL
Dell PowerScale OneFS 9.5.0.0-9.10.0.1 - Unauthenticated Arbitrary File Read, Write, and Delete via NFS Export
CVSS 9.8
CVE-2024-47055
MEDIUM
Mautic - Insecure Direct Object Reference
CVSS 4.3
CVE-2024-54020
LOW
Fortinet FortiManager <7.2.1 - Privilege Escalation
CVSS 2.3
CVE-2024-12812
HIGH
WP ERP < 1.13.4 - Missing Authorization to Terminated Employee Data
CVSS 7.5
CVE-2024-56006
MEDIUM
Jetpack Debug Tools <2.0.1 - Info Disclosure
CVSS 5.3
CVE-2024-51666
MEDIUM
Automattic Tours <1.0.0 - Info Disclosure
CVSS 4.3
CVE-2024-58101
HIGH
Samsung Galaxy Buds - Info Disclosure
CVSS 8.1
CVE-2024-13420
MEDIUM
G5Theme April Framework <5.1 - Authenticated Missing Authorization via AJAX Actions
CVSS 4.3
CVE-2024-13419
MEDIUM
G5Theme April Framework < 5.1 - Authenticated Stored Cross-Site Scripting via saveOptions() and importThemeOptions()
CVSS 6.4
CVE-2024-13307
MEDIUM
Reales WP - Real Estate WordPress Theme <2.1.2 - Info Disclosure
CVSS 5.3
CVE-2024-12244
MEDIUM
GitLab 17.7-17.9.6, 17.10-17.10.4, 17.11 - Missing Authorization
CVSS 4.3
CVE-2024-53591
CRITICAL
Seclore v3.27.5.0 - Unauthenticated Authentication Bypass via Brute Force Attack
CVSS 9.8
CVE-2024-13776
HIGH
ZoomSounds WordPress Plugin <= 6.91 - Authenticated Data Modification via dzsap_delete_notice
CVSS 8.1
CVE-2024-13637
MEDIUM
Demo Awesome <1.0.3 - Privilege Escalation
CVSS 6.5
CVE-2024-55070
LOW
mealie 2.2.0 - Broken Object Level Authorization in Household Permissions
CVSS 3.1
CVE-2024-55073
HIGH
mealie v2.2.0 - Broken Object Level Authorization in User Profile Endpoint
CVSS 7.6
CVE-2024-55072
MEDIUM
mealie v2.2.0 - Broken Object Level Authorization in User Profile Endpoint
CVSS 5.4
CVE-2024-13801
HIGH
BWL Advanced FAQ Manager <2.1.4 - DoS
CVSS 8.1
CVE-2024-13737
MEDIUM
Motors - Car Dealer < 1.4.57 - Authenticated Arbitrary Post Deletion & Template Creation
CVSS 4.3
CVE-2024-9096
HIGH
lunary 1.4.28 - Missing Authorization in /checklists/:id PATCH Endpoint
CVSS 7.1
CVE-2024-9095
CRITICAL
lunary v1.4.28 - Authenticated Missing Authorization in BigQuery API Route
CVSS 9.8
CVE-2024-9000
MEDIUM
lunary < 1.4.26 - Missing Authorization in checklists.post() Endpoint
CVSS 6.5
CVE-2024-8999
HIGH
lunary < 1.4.26 - Unauthenticated Database Export via BigQuery Endpoint
CVSS 7.5
Details
Vulnerabilities
8,345
Exploit Likelihood
High