← Back
CWE-285

1,566 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,566)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Merlinsboard Project
1Merlinsboard
Nov 21, 2024
Jan 9, 2023
N/A· v4
6.5 MEDIUM· v3
3.7 LOW· v2
A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of the component Grade Handler. The manipulation leads to improper authorization. The identifier of the...Show more
A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This affects an unknown part of the component Grade Handler. The manipulation leads to improper authorization. The identifier of the patch is 134f5481e2914b7f096cd92a22b1e6bcb8e6dfe5. It is recommended to apply a patch to fix this issue. The identifier VDB-217713 was assigned to this vulnerability.Show less
1Forged Alliance Forever Project
1Forged Alliance Forever
Jun 17, 2026
Jan 6, 2023
N/A· v4
7.5 HIGH· v3
4.1 MEDIUM· v2
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to impro...Show more
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named 6880971bd3d73d942384aff62d53058c206ce644. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217555.Show less
1Froxlor
1Froxlor
Jun 17, 2026
Dec 31, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
1Huawei
1Aslan Al10 Firmware
Jun 17, 2026
Dec 28, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain file.
1Usememos
1Memos
Jun 17, 2026
Dec 28, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.
1Usememos
1Memos
Jun 17, 2026
Dec 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.
1Mozilla
1Thunderbird
Jun 17, 2026
Dec 22, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.
1Dataprobe
12Iboot Pdu4 N20 Firmware
Iboot Pdu4a N15 FirmwareIboot Pdu4a N20 Firmware+9 more
Jun 17, 2026
Dec 21, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the va...Show more
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate when a valid connection is established with the database. However, these PHP pages do not verify the validity of a user. Attackers could leverage this lack of verification to read the state of outlets. Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Dec 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.
1Openfga
1Openfga
Jun 17, 2026
Dec 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypa...Show more
OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal security assessment, it was discovered that OpenFGA version 0.3.0 is vulnerable to authorization bypass under certain conditions. This issue has been patched in version 0.3.1 and is backward compatible. Show less
1Transposh
1Transposh Wordpress Translation
Jun 17, 2026
Dec 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient validation of setting...Show more
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticated users in versions up to, and including, 1.0.9.6. This is due to insufficient validation of settings on the 'tp_translation' AJAX action which makes it possible for unauthenticated attackers to bypass any restrictions and influence the data shown on the site. Please note this is a separate issue from CVE-2022-2461. Notes from the researcher: When installed Transposh comes with a set of pre-configured options, one of these is the "Who can translate" setting under the "Settings" tab. However, this option is largely ignored, if Transposh has enabled its "autotranslate" feature (it's enabled by default) and the HTTP POST parameter "sr0" is larger than 0. This is caused by a faulty validation in "wp/transposh_db.php."Show less
1Fp Newsletter Project
1Fp Newsletter
Jun 17, 2026
Dec 14, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone...Show more
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction operations.Show less
1Google
1Android
Jun 17, 2026
Dec 8, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.
1Samsung
1Exynos Firmware
Jun 17, 2026
Dec 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.
1Samsung
1Billing
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.
1Google
1Android
Jun 17, 2026
Nov 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
1Google
1Android
Jun 17, 2026
Nov 9, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
1Discourse
1Discourse
Jun 17, 2026
Nov 2, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the...Show more
Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single email address can enter any non-admin user's email and gain access to their account when accepting the invitation. All users should upgrade to the latest version. A workaround is temporarily disabling invitations with `SiteSetting.max_invites_per_day = 0` or scope them to individual email addresses.Show less
1Sick
2Flx3 Cpuc1 Firmware
Flx3 Cpuc2 Firmware
Jun 17, 2026
Oct 31, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2 running an affected firmware version to potentially impact the availability of the FlexiCompact.
1Nextcloud
2Nextcloud Enterprise Server
Nextcloud Server
Jun 17, 2026
Oct 27, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of informat...Show more
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and 24.0.5 contains patches for this issue. No known workarounds are available.Show less