The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Volume of CVEs assigned to CWE-862 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8,727 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0543CRITICAL It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code exec | Feb 18, 2022 | 10.0 | 98 | YES | YES |
CVE-2025-20362HIGH Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by | Sep 25, 2025 | 8.6 | 97 | YES | YES |
CVE-2023-52163HIGH Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | Feb 3, 2025 | 8.8 | 97 | YES | YES |
CVE-2021-39226HIGH Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by ac | Oct 5, 2021 | 7.3 | 97 | YES | YES |
CVE-2025-6205CRITICAL A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application. | Aug 4, 2025 | 9.1 | 96 | YES | YES |
CVE-2021-30657MEDIUM A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekee | Sep 8, 2021 | 5.5 | 91 | YES | YES |
CVE-2021-21978CRITICAL VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file | Mar 3, 2021 | 9.8 | 91 | NO | YES |
CVE-2023-6875CRITICAL The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification | Jan 11, 2024 | 9.8 | 90 | NO | YES |
CVE-2022-1329HIGH The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboa | Apr 19, 2022 | 8.8 | 89 | NO | YES |
CVE-2021-21307CRITICAL Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.9 | Feb 11, 2021 | 9.8 | 89 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.