CWE-285
1,315 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVEs (1,315)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the component Configuration Center. The manipulation leads to impr...Show more |
1Leechesnutt 1Slick Social Share Buttons Apr 8, 2026 Jan 11, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcssb_ajax_update' function in versions up to, and including, 2.4.11. This...Show more |
1Freeamigos 1Manage Notification E Mails Apr 8, 2026 Jan 11, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthentica...Show more |
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may be able to access removable volumes without user consent. |
The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests. |
Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/miss...Show more |
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed |
An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or backup the full system configuration via HTTP or HTTPS requests. |
1Hitachi 1System Management Unit Firmware Nov 21, 2024 Dec 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access...Show more |
1Hitachi 1Vantara Hitachi Network Attached Storage Nov 21, 2024 Dec 5, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and dia...Show more |
NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. A bad actor could create an empty/mock...Show more |
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API...Show more |
The Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized. |
1Intel 1Battery Life Diagnostic Tool Nov 21, 2024 Nov 14, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a privilaged user to potentially enable escalation of privilege via local access. |
1Intel 2Quickassist Technology Firmware Quickassist Technology LibraryNov 21, 2024 Nov 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. |
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via...Show more |
1Prestashop 1Customer Reassurance Block Nov 21, 2024 Nov 8, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassurance module, a BO user can modify the ht...Show more |
Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id. |
1Qualcomm 220315 5g Iot Modem Firmware 9205 Lte Modem FirmwareAqt1000 Firmware+217 moreAug 11, 2025 Nov 7, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Cryptographic issue in HLOS during key management. |
Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91. |