CWE-285
1,566 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVEs (1,566)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
openwhyd is vulnerable to Improper Authorization |
HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possible for registered users to become unauthorized members of private Spaces. Versions 1.10.3 and 1.9.3 c...Show more |
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet. |
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation. |
Dell EMC Networker versions prior to 19.5 contain an Improper Authorization vulnerability. Any local malicious user with networker user privileges may exploit this vulnerability to upload malicious file to unauthorized l...Show more |
4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to bypass authentication by code injection in cookie, and arbitrarily manipulate the system or interrupt s...Show more |
1Aifu 1Cashier Accounting Management System Jun 17, 2026 Nov 16, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general user’s permission, the remote attacker can access account information except passwords by crafting URL...Show more |
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authori...Show more |
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only. |
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/R...Show more |
1Atlassian 2Jira Data Center Jira ServerJun 17, 2026 Nov 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configurations via an Improper Authorization vulnerability in the /secure/admin/ConfigureB...Show more |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreJun 17, 2026 Oct 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the `ReplicationSet...Show more |
Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempt...Show more |
1Inhandnetworks 1Ir615 Firmware Jun 17, 2026 Oct 19, 2021 N/A· v4 8.5 HIGH· v3 6.0 MEDIUM· v2 InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have ful...Show more |
1Huaju 1Easytest Online Learning Test Platform Jun 17, 2026 Oct 15, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by craft...Show more |
1Xinheinformation 1Xinhe Teaching Platform System Jun 17, 2026 Oct 15, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s privilege, remote attackers can access the content of other users’ message boards by crafting URL parame...Show more |
1Xinheinformation 1Xinhe Teaching Platform System Jun 17, 2026 Oct 15, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’s privilege, remote attackers can access and edit other users’ tutorial schedule by crafting URL par...Show more |
1Xinheinformation 1Xinhe Teaching Platform System Jun 17, 2026 Oct 15, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user’s privilege, remote attackers can access and edit other users’ credential and personal information...Show more |
Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that involves bypassing policy restrictions on regular users. Normally, chec...Show more |
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker could change the user profile of any user without proper authorization. With this, the attacker could change...Show more |