CWE-285
1,566 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVEs (1,566)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions. |
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. |
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. |
2Cobbler Project Fedoraproject2Cobbler FedoraJun 17, 2026 Mar 11, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2. |
Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0. |
Improper Authorization in GitHub repository webmin/webmin prior to 1.990. |
1Airspan 5A5x Firmware C5c FirmwareC5x Firmware+2 moreJun 17, 2026 Feb 18, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple...Show more |
Improper Authorization in Packagist librenms/librenms prior to 22.2.0. |
Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity. |
When a password reset or password change flow with an authentication policy is configured and the adapter in the reset or change policy supports multiple parallel reset flows, an existing user can reset another existing...Show more |
1Acronis 4Agent Cyber ProtectCyber Protect Home Office+1 moreJun 17, 2026 Feb 4, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acr...Show more |
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device. |
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword con...Show more |
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword con...Show more |
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist. |
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission |
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address. |
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode. |
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information. |
4Aeotec SamsungSilabs+1 more6500 Series Firmware 700 Series FirmwareSth Eth 200+3 moreJun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6...Show more |