CWE-862 · 9,343 records
Missing Authorization
CVEs in this class
9,363 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2022-0543Weaponized | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Critical10.0 | KEV | 99.4% | Feb 18, 2022 |
94Now | CVE-2023-52163Weaponized | Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection.digiever · ds-2105 pro firmware · CWE-862 | High8.8 | KEV | 96.9% | Feb 3, 2025 |
90Now | CVE-2025-20362Weaponized | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTcisco · adaptive security appliance software · CWE-862 | High8.6 | KEV | 87.1% | Sep 25, 2025 |
89Now | CVE-2024-57726Weaponized | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excesimple-help · simplehelp · CWE-862 | Critical9.9 | KEV | 66.6% | Jan 15, 2025 |
88Now | CVE-2025-6205Weaponized | Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 20253ds · delmia apriso · CWE-862 | Critical9.1 | KEV | 73.3% | Aug 4, 2025 |
73This week | CVE-2021-30657Weaponized | A logic issue was addressed with improved state management.apple · mac os x · CWE-862 | Medium5.5 | KEV | 68.5% | Sep 8, 2021 |
66This week | CVE-2021-21307Weaponized | Remote Code Exploit in Lucee Adminlucee · lucee server · CWE-862 | Critical9.8 | — | 89.2% | Feb 11, 2021 |
65This week | CVE-2020-8772Weaponized | The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php.revmakx · infinitewp client · CWE-862 | Critical9.8 | — | 88.0% | Feb 6, 2020 |
65This week | CVE-2018-6000Weaponized | An issue was discovered in AsusWRT before 3.0.0.4.384_10007.asus · asuswrt · CWE-862 | Critical9.8 | — | 85.2% | Jan 22, 2018 |
63This week | CVE-2023-26035Weaponized | ZoneMinder vulnerable to Missing Authorizationzoneminder · zoneminder · CWE-862 | Critical9.8 | — | 80.5% | Feb 24, 2023 |
63This week | CVE-2019-15954Weaponized | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-862 | Critical9.9 | — | 78.7% | Sep 5, 2019 |
63This week | CVE-2021-30713Weaponized | A permissions issue was addressed with improved validation.apple · mac os x · CWE-862 | High7.8 | KEV | 7.0% | Sep 8, 2021 |
62This week | CVE-2024-41730No exploit | Missing Authentication check in SAP BusinessObjects Business Intelligence Platformsap · business objects business intelligence platform · CWE-862 | Critical9.8 | — | 75.9% | Aug 13, 2024 |
62This week | CVE-2021-37976Weaponized | Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive infogoogle · chrome · CWE-862 | Medium6.5 | KEV | 19.9% | Oct 8, 2021 |
60This week | CVE-2022-23944Proof of concept | Apache ShenYu 2.4.1 Improper access controlapache · shenyu · CWE-862 | Critical9.1 | — | 79.0% | Jan 25, 2022 |
60This week | CVE-2021-45467Proof of concept | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.phcontrol-webpanel · webpanel · CWE-862 | Critical9.8 | — | 70.7% | Dec 26, 2022 |
59Plan | CVE-2021-32172Proof of concept | Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.maianscriptworld · maian cart · CWE-862 | Critical9.8 | — | 66.4% | Oct 7, 2021 |
57Plan | CVE-2024-31997No exploit | XWiki Platform remote code execution from account through UIExtension parametersxwiki · xwiki · CWE-862 | High8.8 | — | 73.9% | Apr 10, 2024 |
57Plan | CVE-2025-11833Proof of concept | Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Losaadiqbal · post smtp – complete email deliverability and smtp solution with email logs, alerts, backup smtp & mobile app · CWE-862 | Critical9.8 | — | 60.3% | Nov 1, 2025 |
55Plan | CVE-2018-10093Proof of concept | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.audiocodes · 420hd ip phone firmware · CWE-862 | High8.8 | — | 68.2% | Mar 21, 2019 |
55Plan | CVE-2024-11972Proof of concept | Hunk Companion < 1.9.0 - Unauthenticated Plugin Installationthemehunk · hunk companion · CWE-862 | Critical9.8 | — | 54.5% | Dec 31, 2024 |
55Plan | CVE-2025-5394Proof of concept | Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installationbearsthemes · alone – charity multipurpose non-profit wordpress theme · CWE-862 | Critical9.8 | — | 52.8% | Jul 15, 2025 |
54Plan | CVE-2018-1217Proof of concept | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1dell · emc avamar · CWE-862 | Critical9.8 | — | 50.9% | Apr 9, 2018 |
54Plan | CVE-2020-36239No exploit | Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 batlassian · jira data center · CWE-862 | Critical9.8 | — | 49.8% | Jul 29, 2021 |
54Plan | CVE-2017-9232Weaponized | Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing canonical · juju · CWE-862 | Critical9.8 | — | 48.5% | May 27, 2017 |
- CVE-2022-0543100Now
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
CriticalCVSS 10.0KEVWeaponizedEPSS 99%redis · redisFeb 18, 2022
- CVE-2023-5216394Now
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection.
HighCVSS 8.8KEVWeaponizedEPSS 97%digiever · ds-2105 pro firmwareFeb 3, 2025
- CVE-2025-2036290Now
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FT
HighCVSS 8.6KEVWeaponizedEPSS 87%cisco · adaptive security appliance softwareSep 25, 2025
- CVE-2024-5772689Now
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with exce
CriticalCVSS 9.9KEVWeaponizedEPSS 67%simple-help · simplehelpJan 15, 2025
- CVE-2025-620588Now
Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
CriticalCVSS 9.1KEVWeaponizedEPSS 73%3ds · delmia aprisoAug 4, 2025
- CVE-2021-3065773This week
A logic issue was addressed with improved state management.
MediumCVSS 5.5KEVWeaponizedEPSS 69%apple · mac os xSep 8, 2021
- CVE-2021-2130766This week
Remote Code Exploit in Lucee Admin
CriticalCVSS 9.8WeaponizedEPSS 89%lucee · lucee serverFeb 11, 2021
- CVE-2020-877265This week
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php.
CriticalCVSS 9.8WeaponizedEPSS 88%revmakx · infinitewp clientFeb 6, 2020
- CVE-2018-600065This week
An issue was discovered in AsusWRT before 3.0.0.4.384_10007.
CriticalCVSS 9.8WeaponizedEPSS 85%asus · asuswrtJan 22, 2018
- CVE-2023-2603563This week
ZoneMinder vulnerable to Missing Authorization
CriticalCVSS 9.8WeaponizedEPSS 80%zoneminder · zoneminderFeb 24, 2023
- CVE-2019-1595463This week
An issue was discovered in Total.js CMS 12.0.0.
CriticalCVSS 9.9WeaponizedEPSS 79%totaljs · total.js cmsSep 5, 2019
- CVE-2021-3071363This week
A permissions issue was addressed with improved validation.
HighCVSS 7.8KEVWeaponizedEPSS 7%apple · mac os xSep 8, 2021
- CVE-2024-4173062This week
Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
CriticalCVSS 9.8No exploitEPSS 76%sap · business objects business intelligence platformAug 13, 2024
- CVE-2021-3797662This week
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive info
MediumCVSS 6.5KEVWeaponizedEPSS 20%google · chromeOct 8, 2021
- CVE-2022-2394460This week
Apache ShenYu 2.4.1 Improper access control
CriticalCVSS 9.1Proof of conceptEPSS 79%apache · shenyuJan 25, 2022
- CVE-2021-4546760This week
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.ph
CriticalCVSS 9.8Proof of conceptEPSS 71%control-webpanel · webpanelDec 26, 2022
- CVE-2021-3217259Plan
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
CriticalCVSS 9.8Proof of conceptEPSS 66%maianscriptworld · maian cartOct 7, 2021
- CVE-2024-3199757Plan
XWiki Platform remote code execution from account through UIExtension parameters
HighCVSS 8.8No exploitEPSS 74%xwiki · xwikiApr 10, 2024
- CVE-2025-1183357Plan
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Lo
CriticalCVSS 9.8Proof of conceptEPSS 60%saadiqbal · post smtp – complete email deliverability and smtp solution with email logs, alerts, backup smtp & mobile appNov 1, 2025
- CVE-2018-1009355Plan
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
HighCVSS 8.8Proof of conceptEPSS 68%audiocodes · 420hd ip phone firmwareMar 21, 2019
- CVE-2024-1197255Plan
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
CriticalCVSS 9.8Proof of conceptEPSS 54%themehunk · hunk companionDec 31, 2024
- CVE-2025-539455Plan
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
CriticalCVSS 9.8Proof of conceptEPSS 53%bearsthemes · alone – charity multipurpose non-profit wordpress themeJul 15, 2025
- CVE-2018-121754Plan
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1
CriticalCVSS 9.8Proof of conceptEPSS 51%dell · emc avamarApr 9, 2018
- CVE-2020-3623954Plan
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 b
CriticalCVSS 9.8No exploitEPSS 50%atlassian · jira data centerJul 29, 2021
- CVE-2017-923254Plan
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing
CriticalCVSS 9.8WeaponizedEPSS 49%canonical · jujuMay 27, 2017