VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1333 CVEsRSS

CVE-2024-32532Medium· 5.3
2y ago

Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6.

Missing Authorization vulnerability in SiteGround Speed Optimizer.This issue affects Speed Optimizer: from n/a through 7.4.6.

▾ SunlitEPSS 0.52%via NVD
CVE-2024-32518Medium· 5.3
2y ago

Missing Authorization vulnerability in Pepro Dev

Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.0.

▾ SunlitEPSS 0.38%via NVD
CVE-2024-22257High· 8.2
2y ago

In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control whe…

In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to 6.2.3, an application is possible vulnerable to broken access control whe…

▾ TwilightEPSS 0.96%via NVD
CVE-2024-0829Medium· 4.3
2y ago

The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0

The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0. This is due to missing or incorrect capability checks on several ajax actions. This m…

▾ Sunlitnajeebmedia · comments_extra_fields_for_post,_pages_and_cptEPSS 0.53%via NVD
CVE-2022-35293Critical· 9.1
4y ago

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and in…

▾ Midnightsap · enable_now_managerEPSS 0.74%via NVD
CVE-2021-44595High· 8.8PoC
4y ago

Wondershare Dr

Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM pri…

▾ Midnightwondershare · dr.foneEPSS 21%via NVD
CVE-2020-25366Critical· 9.1
4y ago

An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.

An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.

▾ Midnightdlink · dir-823g_firmwareEPSS 2.5%via NVD
CVE-2020-23735High· 7.8
5y ago

In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability

In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constructed program to increase user privileges

▾ Twilightsaibo · cyber_game_acceleratorEPSS 0.31%via NVD
CVE-2017-15680Medium· 6.5
5y ago

In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.

In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.

▾ Sunlitcraftercms · crafter_cmsEPSS 0.75%via NVD
CVE-2020-29006Critical· 9.8
5y ago

MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.

MISP before 2.4.135 lacks an ACL check, related to app/Controller/GalaxyElementsController.php and app/Model/GalaxyElement.php.

▾ Midnightmisp-project · mispEPSS 1.3%via NVD
CVE-2020-15412Medium· 4.3
6y ago

An issue was discovered in MISP 2.4.128

An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.

▾ Sunlitmisp-project · mispEPSS 0.69%via NVD
CVE-2020-14969High· 7.5
6y ago

app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations

app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.

▾ Twilightmisp-project · mispEPSS 1.3%via NVD
CVE-2019-9482Medium· 5.3
7y ago

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for

In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (…

▾ Sunlitmisp-project · mispEPSS 0.75%via NVD
CWE-862 vulnerabilities (CVEs) — page 45 · VulnSea