Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-862

MITRE ↗

Missing Authorization

472
CRITICAL
2,109
HIGH
6,422
MEDIUM
212
LOW
9,386 CVEs · Page 156/188
5.5
CVE-2023-42676

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. Th

5.5
CVE-2023-42677

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. Th

5.5
CVE-2023-42678

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. Th

5.5
CVE-2023-42697

In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check.

5.5
CVE-2023-42698

In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check.

5.5
CVE-2023-42699

In omacp service, there is a possible way to write permission usage records of an app due to a missing permission check.

5.5
CVE-2023-42700

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42701

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42702

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42703

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42704

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. Th

5.5
CVE-2023-42705

In imsservice, there is a possible way to write permission usage records of an app due to a missing permission check. Th

5.5
CVE-2023-42706

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42707

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42708

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42709

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42710

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42711

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42712

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42713

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42714

In firewall service, there is a possible way to write permission usage records of an app due to a missing permission che

5.5
CVE-2023-42730

In IMS service, there is a possible way to write permission usage records of an app due to a missing permission check. T

5.5
CVE-2023-42732

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with

5.5
CVE-2023-42733

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with

5.5
CVE-2023-42734

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with

5.5
CVE-2023-42737

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission chec

5.5
CVE-2023-42741

In telecom service, there is a possible way to write permission usage records of an app due to a missing permission chec

5.5
CVE-2023-42742

In sysui, there is a possible missing permission check. This could lead to local denial of service with no additional ex

5.5
CVE-2023-42744

In telecom service, there is a possible missing permission check. This could lead to local denial of service with no add

5.5
CVE-2023-42749

In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission

5.4
CVE-2023-0402

The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sever

5.4
CVE-2023-0404

The Events Made Easy plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev

5.4
CVE-2023-23611

LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provid

5.4
CVE-2023-0713

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-0712

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-0719

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-0718

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-0684

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-0711

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-0715

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-0716

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-0717

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-0720

The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a

5.4
CVE-2023-1022

The WP Meta SEO plugin for WordPress is vulnerable to unauthorized options update due to a missing capability check on t

5.4
CVE-2023-1023

The WP Meta SEO plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability ch

5.4
CVE-2020-36667

The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to unauthorized back-up location changes

5.4
CVE-2023-2716

The Groundhogg plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missi

5.4
CVE-2023-2945

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.

5.4
CVE-2023-2547

The Feather Login Page plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check

5.4
CVE-2023-3053

The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab

Frequently Asked Questions

What is CWE-862?

CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-862?

There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.

How can I protect against CWE-862 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.

Detect CWE-862 Vulnerabilities

CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.

Get Started