CWE-285
1,315 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVEs (1,315)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Digium 2Asterisk Certified AsteriskMay 6, 2026 Dec 12, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 11.6-cert16 and 13.x before 13.8-cert4. The chan_sip channel driver has...Show more |
1Ge 2Bently Nevada 3500/22m Serial Firmware Bently Nevada 3500/22m Usb FirmwareMay 6, 2026 Nov 25, 2016 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier for remote attackers to obtain privileged access via unspecified vectors. |
The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with rest...Show more |
1Wptf Image Gallery Project 1Wptf Image Gallery May 6, 2026 Oct 6, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Remote file download vulnerability in wptf-image-gallery v1.03 |
2Charybdis Project Debian2Charybdis Debian LinuxMay 6, 2026 Sep 21, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter. |
EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack. |
1Microsoft 3Windows 10 Windows 8.1Windows Rt 8.1May 6, 2026 Sep 14, 2016 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it easier for remote attackers to determine passwords via a brute-force attac...Show more |
1Huawei 6Rh1288 V3 Server Firmware Rh2288 V3 Server FirmwareRh2288h V3 Server Firmware+3 moreMay 6, 2026 Sep 7, 2016 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 s...Show more |
2Netgear Nuuo3Nvrmini 2 NvrsoloReadynas SurveillanceMay 6, 2026 Aug 31, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefc...Show more |
1Moxa 2Oncell G3001 Firmware Oncell G3100v2 FirmwareMay 6, 2026 Aug 24, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force...Show more |
3Debian HaxxOpensuse3Debian Linux LeapLibcurlMay 6, 2026 Aug 10, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously c...Show more |
1Rockwellautomation 1Factorytalk Energrymetrix May 6, 2026 Jul 28, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. |
WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote attackers to b...Show more |
The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote attack...Show more |
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that...Show more |