Vulnerabilities (CVE)

Filtered by CWE-862
Total 6613 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-39994 1 Reputeinfosystems 1 Armember 2026-01-23 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember Premium: from n/a through 5.9.2.
CVE-2025-59968 1 Juniper 19 Space Security Director, Srx1500, Srx1600 and 16 more 2026-01-23 N/A 8.6 HIGH
A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify metadata via the web interface.  Tampering with this metadata can result in managed SRX Series devices permitting network traffic that should otherwise be blocked by policy, effectively bypassing intended security controls. This issue affects Junos Space Security Director * all versions prior to 24.1R3 Patch V4 This issue does not affect managed cSRX Series devices.
CVE-2024-31270 1 Reputeinfosystems 1 Arforms Form Builder 2026-01-23 N/A 7.6 HIGH
Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.
CVE-2023-47788 1 Automattic 1 Jetpack 2026-01-23 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
CVE-2025-52954 1 Juniper 1 Junos Os Evolved 2026-01-23 N/A 7.8 HIGH
A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain root privileges, leading to a system compromise. Any low-privileged user with the capability to send packets over the internal VRF can execute arbitrary Junos commands and modify the configuration, and thus compromise the system.  This issue affects Junos OS Evolved:  * All versions before 22.2R3-S7-EVO,  * from 22.4 before 22.4R3-S7-EVO,  * from 23.2 before 23.2R2-S4-EVO,  * from 23.4 before 23.4R2-S5-EVO,  * from 24.2 before 24.2R2-S1-EVO * from 24.4 before 24.4R1-S2-EVO, 24.4R2-EVO.
CVE-2025-14757 1 Stylemixthemes 1 Cost Calculator Builder 2026-01-23 N/A 5.3 MEDIUM
The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Payment Status Bypass in all versions up to, and including, 3.6.9 only when used in combination with Cost Calculator Builder PRO. This is due to the complete_payment AJAX action being registered via wp_ajax_nopriv, making it accessible to unauthenticated users, and the complete() function only verifying a nonce without checking user capabilities or order ownership. Since nonces are exposed to all visitors via window.ccb_nonces in the page source, any unauthenticated attacker can mark any order's payment status as "completed" without actual payment.
CVE-2025-14457 1 Codedropz 1 Contact Form 7 2026-01-23 N/A 3.7 LOW
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ownership check in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.9.2. This makes it possible for unauthenticated attackers to delete arbitrary uploaded files when the "Send attachments as links" setting is enabled.
CVE-2025-39353 1 Themegoods 1 Grand Restaurant 2026-01-22 N/A 5.3 MEDIUM
Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
CVE-2025-39352 1 Themegoods 1 Grand Restaurant 2026-01-22 N/A 8.2 HIGH
Missing Authorization vulnerability in ThemeGoods Grand Restaurant WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
CVE-2025-13781 1 Gitlab 1 Gitlab 2026-01-22 N/A 6.5 MEDIUM
GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.
CVE-2023-47180 1 Xlplugins 1 Finale 2026-01-22 N/A 6.5 MEDIUM
Missing Authorization vulnerability in XLPlugins Finale Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Finale Lite: from n/a through 2.16.0.
CVE-2024-54217 1 Reputeinfosystems 1 Arforms 2026-01-22 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Repute info systems ARForms.This issue affects ARForms: from n/a through 6.4.1.
CVE-2026-0506 1 Sap 1 Netweaver Application Server Abap 2026-01-22 N/A 8.1 HIGH
Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data accessible via FORMs and invoke system functionality exposed via FORMs, resulting in a high impact on integrity and availability, while confidentiality remains unaffected.
CVE-2025-13772 1 Gitlab 1 Gitlab 2026-01-22 N/A 7.1 HIGH
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API requests.
CVE-2025-64729 1 Aveva 1 Process Optimization 2026-01-22 N/A 8.1 HIGH
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optimization project files, embed code, and escalate their privileges to the identity of a victim user who subsequently interacts with the project files.
CVE-2025-39482 1 Imithemes 1 Eventer 2026-01-22 N/A 4.3 MEDIUM
Missing Authorization vulnerability in imithemes Eventer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventer: from n/a before 3.11.4.
CVE-2024-37415 1 E2pdf 1 E2pdf 2026-01-21 N/A 5.4 MEDIUM
Missing Authorization vulnerability in E2Pdf.Com allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects e2pdf: from n/a through 1.20.27.
CVE-2024-37440 1 Church Admin Project 1 Church Admin 2026-01-21 N/A 4.3 MEDIUM
Missing Authorization vulnerability in Andy Moyle Church Admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through 4.4.4.
CVE-2024-31281 1 Church Admin Project 1 Church Admin 2026-01-21 N/A 6.3 MEDIUM
Missing Authorization vulnerability in Andy Moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through 4.1.6.
CVE-2024-30505 1 Church Admin Project 1 Church Admin 2026-01-21 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.18.