CWE-285
1,315 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVEs (1,315)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Tauri is a framework for building binaries for all major desktop platforms. The 1.4.0 release includes a regression on the Filesystem scope check for dotfiles on Unix. Previously dotfiles were not implicitly allowed by t...Show more |
An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings even though the opt...Show more |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
1Microsoft 4Windows Server 2012 Windows Server 2016Windows Server 2019+1 moreNov 21, 2024 Jun 14, 2023 N/A· v4 7.6 HIGH· v3 N/A· v2 Windows Server Service Security Feature Bypass Vulnerability |
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3....Show more |
By changing the filename parameter in the request, an attacker could
delete any file with the permissions of the Vuforia server account.
|
An attacker with local access to the machine could record the traffic,
which could allow them to resend requests without the server
authenticating that the user or session are valid.
|
1Najeebmedia 1Frontend File Manager Plugin Apr 8, 2026 Jun 7, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This...Show more |
The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up...Show more |
1Tychesoftwares 1Product Input Fields For Woocommerce Apr 8, 2026 Jun 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes...Show more |
The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and including, 2.0.6. This allows authenticated attackers with any capability level to deactivate any plugin o...Show more |
A security defect in Foundry's Comments functionality resulted in the retrieval of attachments to comments not being gated by additional authorization checks. This could enable an authenticated user to inject a prior dis...Show more |
1Qualcomm 81315 5g Iot Modem Firmware Ar8035 FirmwareQca6390 Firmware+78 moreNov 21, 2024 Jun 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. |
1Qualcomm 242315 5g Iot Modem Firmware 8953pro Firmware9205 Lte Modem Firmware+239 moreNov 21, 2024 Jun 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Transient DOS due to improper authorization in Modem |
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level pe...Show more |
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributo...Show more |
Kyverno is a policy engine designed for Kubernetes. In versions of Kyverno prior to 1.10.0, resources which have the `deletionTimestamp` field defined can bypass validate, generate, or mutate-existing policies, even in c...Show more |
1Splunk 2Splunk Splunk Cloud PlatformNov 21, 2024 Jun 1, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, and in Splunk Cloud Platform versions below 9.0.2303.100, an unauthorized user can access the {{/services/indexing/preview}} REST endpoint to overwrite searc...Show more |
1Splunk 2Splunk Splunk Cloud PlatformNov 21, 2024 Jun 1, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 In Splunk Enterprise versions below 9.0.5, 8.2.11. and 8.1.14, and Splunk Cloud Platform versions below 9.0.2303.100, a low-privileged user who holds the ‘user’ role can see the hashed version of the initial user name an...Show more |
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escala...Show more |