CWE-862

High likelihood

Missing Authorization

Parent: CWE-285 - Improper Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

8,346 vulnerabilities with CWE-862
CVE-2024-13370 MEDIUM
Youzify - BuddyPress Community <1.3.2 - Privilege Escalation
CVSS 6.5
CVE-2024-13368 MEDIUM
Youzify - BuddyPress <1.3.2 - Privilege Escalation
CVSS 4.3
CVE-2024-12826 MEDIUM
GoHero Store Customizer - Info Disclosure
CVSS 4.3
CVE-2024-12113 MEDIUM
Youzify < 1.3.3 - Authenticated Unauthorized Data Deletion via Review Deletion Functions
CVSS 4.3
CVE-2024-13698 MEDIUM
Jobify WordPress Theme <= 4.2.7 - Unauthenticated Arbitrary File Upload
CVSS 6.5
CVE-2024-13335 MEDIUM
Spexo Addons for Elementor - Auth Bypass
CVSS 4.3
CVE-2024-13447 MEDIUM
WP Hotel Booking <2.1.6 - Info Disclosure
CVSS 4.3
CVE-2024-13361 MEDIUM
WordPress AI Power: Complete AI Pack <1.8.96 - Auth Bypass
CVSS 6.3
CVE-2024-12879 MEDIUM
QuantumCloud WPBot Pro Wordpress Chatbot <= 13.5.5 - Authenticated Data Modification via Missing Capability Check
CVSS 4.3
CVE-2024-12104 MEDIUM
Atarim < 4.1.0 - Unauthenticated Data Deletion via Missing Capability Check
CVSS 5.3
CVE-2024-12071 MEDIUM
Evergreen Content Poster < 1.4.4 - Unauthenticated Arbitrary Post Deletion via delete_network_post Function
CVSS 5.3
CVE-2024-50967 MEDIUM
Becon DATAGerry <2.2.0 - Info Disclosure
CVSS 6.5
CVE-2024-12370 MEDIUM
WP Hotel Booking <= 2.1.5 - Unauthenticated Room Addition via Missing Capability Check
CVSS 5.3
CVE-2024-13367 MEDIUM
Sandbox plugin <0.4 - Info Disclosure
CVSS 6.5
CVE-2024-46450 HIGH
Tenda AC6 v2.0 Firmware v15.03.06.50 - Missing Authorization
CVSS 8.1
CVE-2024-57682 MEDIUM
D-Link DIR-816 Firmware 816A2_FWv1.10CNB05_R1B011D88210 - Unauthenticated Information Disclosure via d_status.asp
CVSS 6.5
CVE-2024-12614 HIGH
Passwords Manager <= 1.4.8 - Authenticated Unauthorized Data Modification via AJAX Actions
CVSS 7.5
CVE-2024-12427 MEDIUM
Multi Step Form <= 1.7.23 - Unauthenticated Limited File Upload via fw_upload_file AJAX Action
CVSS 5.3
CVE-2024-57726 CRITICAL KEV
SimpleHelp < 5.5.8 - Missing Authorization for API Key Creation
CVSS 9.9
CVE-2024-54470 MEDIUM
iPadOS < 17.7.1 and < 18.1 - Unauthenticated Contacts Access from Lock Screen
CVSS 4.6
CVE-2024-40839 LOW
iPadOS < 17.5 - Unauthenticated Notification Content Exposure from Lock Screen
CVSS 2.4
CVE-2024-56295 MEDIUM
Ays Pro Poll Maker <= 5.5.6 - Missing Authorization
CVSS 6.5
CVE-2024-11851 MEDIUM
NitroPack <1.17.0 - Privilege Escalation
CVSS 4.3
CVE-2024-11848 HIGH
NitroPack <1.17.0 - Info Disclosure
CVSS 8.1
CVE-2024-57757 HIGH
jeewms < 2025.01.01 - Missing Authorization in AuthInterceptor
CVSS 7.5
Details
Vulnerabilities 8,346
Exploit Likelihood High