← Back
CWE-285

1,431 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

JSON object

Loading...

CVEs (1,431)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
11Sf 220 24 Firmware
Sf220 24p FirmwareSf220 48 Firmware+8 more
Jun 17, 2026
Aug 7, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authoriz...Show more
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the web management interface. An attacker could exploit this vulnerability by sending a malicious request to certain parts of the web management interface. Depending on the configuration of the affected switch, the malicious request must be sent via HTTP or HTTPS. A successful exploit could allow the attacker to modify the configuration of an affected device or to inject a reverse shell. This vulnerability affects Cisco Small Business 220 Series Smart Switches running firmware versions prior to 1.1.4.4 with the web management interface enabled. The web management interface is enabled via both HTTP and HTTPS by default.Show less
1Mongodb
1Mongodb
Jun 17, 2026
Aug 6, 2019
N/A· v4
7.1 HIGH· v3
6.0 MEDIUM· v2
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of del...Show more
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This issue affects MongoDB Server v4.0 versions prior to 4.0.9; MongoDB Server v3.6 versions prior to 3.6.13 and MongoDB Server v3.4 versions prior to 3.4.22. Workaround: After deleting one or more users, restart any nodes which may have had active user authorization sessions. Refrain from creating user accounts with the same name as previously deleted accounts.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.7 MEDIUM· v3
7.9 HIGH· v2
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.8 LOW· v3
2.1 LOW· v2
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
1Printeron
1Central Print Services
Nov 21, 2024
Jul 20, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them....Show more
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass the session checks (that would otherwise logout a low-privileged user) by calling the core print job components directly via crafted HTTP GET and POST requests.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Jul 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they creat...Show more
GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Jul 10, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
GitLab EE, version 11.5 before 11.5.1, is vulnerable to an insecure object reference issue that permits a user with Reporter privileges to view the Jaeger Tracing Operations page.
1Gitlab
1Gitlab
Nov 21, 2024
Jul 10, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token...Show more
GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.Show less
1Cloudera
1Cdh
Nov 21, 2024
Jul 3, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.
1Dlink
1Dcs 1130 Firmware
Nov 21, 2024
Jul 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on D-Link DCS-1130 devices. The device requires that a user logging to the device to provide a username and password. However, the device does not enforce the same restriction on a specific URL th...Show more
An issue was discovered on D-Link DCS-1130 devices. The device requires that a user logging to the device to provide a username and password. However, the device does not enforce the same restriction on a specific URL thereby allowing any attacker in possession of that to view the live video feed. The severity of this attack is enlarged by the fact that there more than 100,000 D-Link devices out there.Show less
1Google
1Chrome
Nov 21, 2024
Jun 27, 2019
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Ex...Show more
Insufficient policy enforcement in extensions API in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.Show less
1Google
1Chrome
Nov 21, 2024
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Object lifecycle issue in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass content security policy via a crafted HTML page.
1Google
1Chrome
Nov 21, 2024
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.
1Google
1Chrome
Nov 21, 2024
Jun 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in site isolation in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass site isolation via a crafted HTML page.
1Moodle
1Moodle
Jun 17, 2026
Jun 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
1Cisco
3Rv110w Firmware
Rv130w FirmwareRv215w Firmware
Jun 17, 2026
Jun 20, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability i...Show more
A vulnerability in the web interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to acquire the list of devices that are connected to the guest network. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing a specific URI on the web interface of the router.Show less
1Cisco
3Rv110w Firmware
Rv130w FirmwareRv215w Firmware
Jun 17, 2026
Jun 20, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due...Show more
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to access the syslog file on an affected device. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing the URL for the syslog file. A successful exploit could allow the attacker to access the information contained in the file.Show less
1Cisco
3Rv110w Firmware
Rv130w FirmwareRv215w Firmware
Jun 17, 2026
Jun 20, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to disconnect clients that are connected to the guest network on an affect...Show more
A vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to disconnect clients that are connected to the guest network on an affected router. The vulnerability is due to improper authorization of an HTTP request. An attacker could exploit this vulnerability by accessing the URL for device disconnection and providing the connected device information. A successful exploit could allow the attacker to deny service to specific clients that are connected to the guest network.Show less