The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif
Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are
Kanboard is open source project management software that focuses on the Kanban methodology. A vulnerability related to a
The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check
The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'tw
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif
A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read pe
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the
S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization
S/4HANA Manage (Withholding Tax Items) - version 106, does not perform necessary authorization checks for an authenticat
The Grid Plus plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing
The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the
Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permi
Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements,
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.Thi
An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4,
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which m
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files
Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 be
A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger
A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated at
The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Me
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized medic
OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an atta
Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vul
Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead
The affected TBox RTUs are missing authorization for running some API commands. An attacker running these commands could
The EventON WordPress plugin before 2.1.2 lacks authentication and authorization in its eventon_ics_download ajax action
HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plug
An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed
Cerebrate before 1.15 lacks the Secure attribute for the session cookie.
An issue was discovered in the MyCrops HiGrade "THC Testing & Cannabi" application 1.0.337 for Android. A remote attacke
Incorrect validation vulnerability of the data entered, allowing an attacker with access to the network on which the a
The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check
IBM UrbanCode Deploy (UCD) 7.1 - 7.1.2.12, 7.2 through 7.2.3.5, and 7.3 through 7.3.2.0 under certain configurations cou
The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missi
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5,
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v
The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in v
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec
The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 v
The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks o
Submitty before v22.06.00 is vulnerable to Incorrect Access Control. An attacker can delete any post in the forum by mod
Prometheus metrics are available without authentication. These expose detailed and sensitive information about the Yugab
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and
The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting a
An issue in simplemobiletools Simple Dialer 5.18.1 allows an attacker to bypass intended access restrictions via interac
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started