Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-
Due to missing authorization an unauthenticated remote attacker can cause a DoS attack by connecting via HTTPS and trigg
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before
Missing Authorization vulnerability in Crocoblock JetElements For Elementor jet-elements allows Accessing Functionality
Missing Authorization vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows Accessing Functionality Not Prope
Missing Authorization vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Accessing Functionality Not
Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Accessing Functionality Not Properly Constrained b
A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 a
Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized l
Missing Authorization vulnerability in enguerranws Import YouTube videos as WP Posts import-youtube-videos-as-wp-post al
The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the
SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user
The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the
Missing Authorization vulnerability in August Infotech Multi-language Responsive Contact Form responsive-contact-form al
Missing Authorization vulnerability in uxper Sala allows Accessing Functionality Not Properly Constrained by ACLs. This
Missing Authorization vulnerability in uxper Nuss nuss allows Accessing Functionality Not Properly Constrained by ACLs.T
Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: f
The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabi
The UiCore Elements – Free Elementor widgets and templates plugin for WordPress is vulnerable to Arbitrary File Read in
Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Acce
Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Exploiting Incorrectly Co
Missing Authorization vulnerability in themefunction WordPress Event Manager, Event Calendar and Booking Plugin eventin-
Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free
Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing
The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_act
Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares fea
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain
Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Cont
Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality
Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constra
Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through
Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.
The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versi
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
Missing Authorization vulnerability in kamleshyadav Miraculous miraculous allows Exploiting Incorrectly Configured Acces
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started