CWE-862 · 9.343 kayıt
Missing Authorization
Bu sınıftaki CVE’ler
9.362 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2022-0543Silahlaştırılmış | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escaperedis · redis · CWE-862 | Kritik10,0 | KEV | %99,4 | 18 Şub 2022 |
94Hemen | CVE-2023-52163Silahlaştırılmış | Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection.digiever · ds-2105 pro firmware · CWE-862 | Yüksek8,8 | KEV | %96,9 | 3 Şub 2025 |
90Hemen | CVE-2025-20362Silahlaştırılmış | Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTcisco · adaptive security appliance software · CWE-862 | Yüksek8,6 | KEV | %87,1 | 25 Eyl 2025 |
89Hemen | CVE-2024-57726Silahlaştırılmış | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excesimple-help · simplehelp · CWE-862 | Kritik9,9 | KEV | %66,6 | 15 Oca 2025 |
88Hemen | CVE-2025-6205Silahlaştırılmış | Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 20253ds · delmia apriso · CWE-862 | Kritik9,1 | KEV | %73,3 | 4 Ağu 2025 |
73Bu hafta | CVE-2021-30657Silahlaştırılmış | A logic issue was addressed with improved state management.apple · mac os x · CWE-862 | Orta5,5 | KEV | %68,5 | 8 Eyl 2021 |
66Bu hafta | CVE-2021-21307Silahlaştırılmış | Remote Code Exploit in Lucee Adminlucee · lucee server · CWE-862 | Kritik9,8 | — | %89,2 | 11 Şub 2021 |
65Bu hafta | CVE-2020-8772Silahlaştırılmış | The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php.revmakx · infinitewp client · CWE-862 | Kritik9,8 | — | %88,0 | 6 Şub 2020 |
65Bu hafta | CVE-2018-6000Silahlaştırılmış | An issue was discovered in AsusWRT before 3.0.0.4.384_10007.asus · asuswrt · CWE-862 | Kritik9,8 | — | %85,2 | 22 Oca 2018 |
63Bu hafta | CVE-2023-26035Silahlaştırılmış | ZoneMinder vulnerable to Missing Authorizationzoneminder · zoneminder · CWE-862 | Kritik9,8 | — | %80,5 | 24 Şub 2023 |
63Bu hafta | CVE-2019-15954Silahlaştırılmış | An issue was discovered in Total.js CMS 12.0.0.totaljs · total.js cms · CWE-862 | Kritik9,9 | — | %78,7 | 5 Eyl 2019 |
63Bu hafta | CVE-2021-30713Silahlaştırılmış | A permissions issue was addressed with improved validation.apple · mac os x · CWE-862 | Yüksek7,8 | KEV | %7,0 | 8 Eyl 2021 |
62Bu hafta | CVE-2024-41730İstismar yok | Missing Authentication check in SAP BusinessObjects Business Intelligence Platformsap · business objects business intelligence platform · CWE-862 | Kritik9,8 | — | %75,9 | 13 Ağu 2024 |
62Bu hafta | CVE-2021-37976Silahlaştırılmış | Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive infogoogle · chrome · CWE-862 | Orta6,5 | KEV | %19,9 | 8 Eki 2021 |
60Bu hafta | CVE-2022-23944Kavram kanıtı | Apache ShenYu 2.4.1 Improper access controlapache · shenyu · CWE-862 | Kritik9,1 | — | %79,0 | 25 Oca 2022 |
60Bu hafta | CVE-2021-45467Kavram kanıtı | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.phcontrol-webpanel · webpanel · CWE-862 | Kritik9,8 | — | %70,7 | 26 Ara 2022 |
59Planlayın | CVE-2021-32172Kavram kanıtı | Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.maianscriptworld · maian cart · CWE-862 | Kritik9,8 | — | %66,4 | 7 Eki 2021 |
57Planlayın | CVE-2024-31997İstismar yok | XWiki Platform remote code execution from account through UIExtension parametersxwiki · xwiki · CWE-862 | Yüksek8,8 | — | %73,9 | 10 Nis 2024 |
57Planlayın | CVE-2025-11833Kavram kanıtı | Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Losaadiqbal · post smtp – complete email deliverability and smtp solution with email logs, alerts, backup smtp & mobile app · CWE-862 | Kritik9,8 | — | %60,3 | 1 Kas 2025 |
55Planlayın | CVE-2018-10093Kavram kanıtı | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.audiocodes · 420hd ip phone firmware · CWE-862 | Yüksek8,8 | — | %68,2 | 21 Mar 2019 |
55Planlayın | CVE-2024-11972Kavram kanıtı | Hunk Companion < 1.9.0 - Unauthenticated Plugin Installationthemehunk · hunk companion · CWE-862 | Kritik9,8 | — | %54,5 | 31 Ara 2024 |
55Planlayın | CVE-2025-5394Kavram kanıtı | Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installationbearsthemes · alone – charity multipurpose non-profit wordpress theme · CWE-862 | Kritik9,8 | — | %52,8 | 15 Tem 2025 |
54Planlayın | CVE-2018-1217Kavram kanıtı | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1dell · emc avamar · CWE-862 | Kritik9,8 | — | %50,9 | 9 Nis 2018 |
54Planlayın | CVE-2020-36239İstismar yok | Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 batlassian · jira data center · CWE-862 | Kritik9,8 | — | %49,8 | 29 Tem 2021 |
54Planlayın | CVE-2017-9232Silahlaştırılmış | Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing canonical · juju · CWE-862 | Kritik9,8 | — | %48,5 | 27 May 2017 |
- CVE-2022-0543100Hemen
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %99redis · redis18 Şub 2022
- CVE-2023-5216394Hemen
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %97digiever · ds-2105 pro firmware3 Şub 2025
- CVE-2025-2036290Hemen
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FT
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %87cisco · adaptive security appliance software25 Eyl 2025
- CVE-2024-5772689Hemen
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with exce
KritikCVSS 9,9KEVSilahlaştırılmışEPSS %67simple-help · simplehelp15 Oca 2025
- CVE-2025-620588Hemen
Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %733ds · delmia apriso4 Ağu 2025
- CVE-2021-3065773Bu hafta
A logic issue was addressed with improved state management.
OrtaCVSS 5,5KEVSilahlaştırılmışEPSS %69apple · mac os x8 Eyl 2021
- CVE-2021-2130766Bu hafta
Remote Code Exploit in Lucee Admin
KritikCVSS 9,8SilahlaştırılmışEPSS %89lucee · lucee server11 Şub 2021
- CVE-2020-877265Bu hafta
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php.
KritikCVSS 9,8SilahlaştırılmışEPSS %88revmakx · infinitewp client6 Şub 2020
- CVE-2018-600065Bu hafta
An issue was discovered in AsusWRT before 3.0.0.4.384_10007.
KritikCVSS 9,8SilahlaştırılmışEPSS %85asus · asuswrt22 Oca 2018
- CVE-2023-2603563Bu hafta
ZoneMinder vulnerable to Missing Authorization
KritikCVSS 9,8SilahlaştırılmışEPSS %80zoneminder · zoneminder24 Şub 2023
- CVE-2019-1595463Bu hafta
An issue was discovered in Total.js CMS 12.0.0.
KritikCVSS 9,9SilahlaştırılmışEPSS %79totaljs · total.js cms5 Eyl 2019
- CVE-2021-3071363Bu hafta
A permissions issue was addressed with improved validation.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %7apple · mac os x8 Eyl 2021
- CVE-2024-4173062Bu hafta
Missing Authentication check in SAP BusinessObjects Business Intelligence Platform
KritikCVSS 9,8İstismar yokEPSS %76sap · business objects business intelligence platform13 Ağu 2024
- CVE-2021-3797662Bu hafta
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive info
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %20google · chrome8 Eki 2021
- CVE-2022-2394460Bu hafta
Apache ShenYu 2.4.1 Improper access control
KritikCVSS 9,1Kavram kanıtıEPSS %79apache · shenyu25 Oca 2022
- CVE-2021-4546760Bu hafta
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.ph
KritikCVSS 9,8Kavram kanıtıEPSS %71control-webpanel · webpanel26 Ara 2022
- CVE-2021-3217259Planlayın
Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.
KritikCVSS 9,8Kavram kanıtıEPSS %66maianscriptworld · maian cart7 Eki 2021
- CVE-2024-3199757Planlayın
XWiki Platform remote code execution from account through UIExtension parameters
YüksekCVSS 8,8İstismar yokEPSS %74xwiki · xwiki10 Nis 2024
- CVE-2025-1183357Planlayın
Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Lo
KritikCVSS 9,8Kavram kanıtıEPSS %60saadiqbal · post smtp – complete email deliverability and smtp solution with email logs, alerts, backup smtp & mobile app1 Kas 2025
- CVE-2018-1009355Planlayın
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
YüksekCVSS 8,8Kavram kanıtıEPSS %68audiocodes · 420hd ip phone firmware21 Mar 2019
- CVE-2024-1197255Planlayın
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
KritikCVSS 9,8Kavram kanıtıEPSS %54themehunk · hunk companion31 Ara 2024
- CVE-2025-539455Planlayın
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
KritikCVSS 9,8Kavram kanıtıEPSS %53bearsthemes · alone – charity multipurpose non-profit wordpress theme15 Tem 2025
- CVE-2018-121754Planlayın
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1
KritikCVSS 9,8Kavram kanıtıEPSS %51dell · emc avamar9 Nis 2018
- CVE-2020-3623954Planlayın
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 b
KritikCVSS 9,8İstismar yokEPSS %50atlassian · jira data center29 Tem 2021
- CVE-2017-923254Planlayın
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing
KritikCVSS 9,8SilahlaştırılmışEPSS %49canonical · juju27 May 2017