CWE-285
1,566 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVEs (1,566)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge....Show more |
The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Sep 27, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not...Show more |
Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to g...Show more |
A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This could allow a separate realm to be accessible to an attacker, permitting ac...Show more |
1Ormazabal 2Ekorccp Firmware Ekorrci FirmwareJun 17, 2026 Sep 19, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive information for the organisation, without being authenticated within the web server. |
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the O...Show more |
1Qualcomm 82205 Firmware 215 Firmware9206 Lte Firmware+79 moreJun 17, 2026 Sep 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE. |
1Qualcomm 82205 Firmware 215 Firmware9206 Lte Firmware+79 moreJun 17, 2026 Sep 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE. |
1Qualcomm 70Aqt1000 Firmware Csrb31024 FirmwareFastconnect 6200 Firmware+67 moreJun 17, 2026 Sep 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA). |
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. Users who used to be subscribed to a private stream and have been removed from it since retain the ability to edit...Show more |
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 14.11.99.28 and Tuleap Enterprise Edition prior to versions 14.10-6 and 14.11-...Show more |
2Fedoraproject Redhat20Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+17 moreJun 17, 2026 Aug 23, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that cou...Show more |
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. |
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. |
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. |
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. |
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. |
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization. |
1Intel 1Next Unit Of Computing Firmware Jun 17, 2026 Aug 11, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable escalation of privilage via local access. |