CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,345 vulnerabilities with CWE-862
CVE-2024-32589 HIGH
UkrSolution Barcode Scanner <1.5.3 - Info Disclosure
CVSS 7.1
CVE-2024-8860 MEDIUM
Tourfic < 2.14.5 - Authenticated Missing Authorization in Order and Visitor Management Functions
CVSS 4.3
CVE-2024-53298 CRITICAL
Dell PowerScale OneFS 9.5.0.0-9.10.0.1 - Unauthenticated Arbitrary File Read, Write, and Delete via NFS Export
CVSS 9.8
CVE-2024-47055 MEDIUM
Mautic - Insecure Direct Object Reference
CVSS 4.3
CVE-2024-54020 LOW
Fortinet FortiManager <7.2.1 - Privilege Escalation
CVSS 2.3
CVE-2024-12812 HIGH
WP ERP < 1.13.4 - Missing Authorization to Terminated Employee Data
CVSS 7.5
CVE-2024-56006 MEDIUM
Jetpack Debug Tools <2.0.1 - Info Disclosure
CVSS 5.3
CVE-2024-51666 MEDIUM
Automattic Tours <1.0.0 - Info Disclosure
CVSS 4.3
CVE-2024-58101 HIGH
Samsung Galaxy Buds - Info Disclosure
CVSS 8.1
CVE-2024-13420 MEDIUM
G5Theme April Framework <5.1 - Authenticated Missing Authorization via AJAX Actions
CVSS 4.3
CVE-2024-13419 MEDIUM
G5Theme April Framework < 5.1 - Authenticated Stored Cross-Site Scripting via saveOptions() and importThemeOptions()
CVSS 6.4
CVE-2024-13307 MEDIUM
Reales WP - Real Estate WordPress Theme <2.1.2 - Info Disclosure
CVSS 5.3
CVE-2024-12244 MEDIUM
GitLab 17.7-17.9.6, 17.10-17.10.4, 17.11 - Missing Authorization
CVSS 4.3
CVE-2024-53591 CRITICAL
Seclore v3.27.5.0 - Unauthenticated Authentication Bypass via Brute Force Attack
CVSS 9.8
CVE-2024-13776 HIGH
ZoomSounds WordPress Plugin <= 6.91 - Authenticated Data Modification via dzsap_delete_notice
CVSS 8.1
CVE-2024-13637 MEDIUM
Demo Awesome <1.0.3 - Privilege Escalation
CVSS 6.5
CVE-2024-55070 LOW
mealie 2.2.0 - Broken Object Level Authorization in Household Permissions
CVSS 3.1
CVE-2024-55073 HIGH
mealie v2.2.0 - Broken Object Level Authorization in User Profile Endpoint
CVSS 7.6
CVE-2024-55072 MEDIUM
mealie v2.2.0 - Broken Object Level Authorization in User Profile Endpoint
CVSS 5.4
CVE-2024-13801 HIGH
BWL Advanced FAQ Manager <2.1.4 - DoS
CVSS 8.1
CVE-2024-13737 MEDIUM
Motors - Car Dealer < 1.4.57 - Authenticated Arbitrary Post Deletion & Template Creation
CVSS 4.3
CVE-2024-9096 HIGH
lunary 1.4.28 - Missing Authorization in /checklists/:id PATCH Endpoint
CVSS 7.1
CVE-2024-9095 CRITICAL
lunary v1.4.28 - Authenticated Missing Authorization in BigQuery API Route
CVSS 9.8
CVE-2024-9000 MEDIUM
lunary < 1.4.26 - Missing Authorization in checklists.post() Endpoint
CVSS 6.5
CVE-2024-8999 HIGH
lunary < 1.4.26 - Unauthenticated Database Export via BigQuery Endpoint
CVSS 7.5
Details
Vulnerabilities 8,345
Exploit Likelihood High