← Back
CWE-863

3,038 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,038)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Galaxy Store
Nov 21, 2024
Apr 11, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.
1Google
1Android
Nov 21, 2024
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission....Show more
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary files access.Show less
1Google
1Android
Nov 21, 2024
Apr 11, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.
1Gitlab
1Gitlab
Nov 21, 2024
Apr 11, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Request...Show more
Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstancesShow less
1Salonbookingsystem
1Salon Booking System
Nov 21, 2024
Apr 11, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data
1Aenrich
1A+hrd
Nov 21, 2024
Apr 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.
1Forcepoint
1One Endpoint
Nov 21, 2024
Apr 4, 2022
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by users with Administrator privileges. This could result in a user disablin...Show more
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by users with Administrator privileges. This could result in a user disabling Forcepoint One Endpoint and the protection offered by it.Show less
1Forcepoint
1One Endpoint
Nov 21, 2024
Apr 4, 2022
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator privileges. This could result in a user disabling anti-tampering mechanism...Show more
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator privileges. This could result in a user disabling anti-tampering mechanisms which would then allow the user to disable Forcepoint One Endpoint and the protection offered by it.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Apr 4, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions startin...Show more
Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.Show less
1Automationdirect
20C0 10are D Firmware
C0 10dd1e D FirmwareC0 10dd2e D Firmware+17 more
Nov 21, 2024
Apr 4, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains u...Show more
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user, the unlocked state does not timeout. If the programming software is interrupted, the PLC remains unlocked. All subsequent programming connections are allowed without authorization. The PLC is only relocked by a power cycle, or when the programming software disconnects correctly.Show less
1Tms Outsource
1Amelia
Nov 21, 2024
Apr 4, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the booking...Show more
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who booked it.Show less
1Phpipam
1Phpipam
Nov 21, 2024
Apr 4, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
1Phpipam
1Phpipam
Feb 24, 2026
Apr 4, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
1Janeczku
1Calibre Web
Nov 21, 2024
Apr 3, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
1Rockwellautomation
1Factorytalk Services Platform
Apr 17, 2025
Apr 1, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security...Show more
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have the same privileges as if they were logged on to the client machine.Show less
1Arista
1Eos
Nov 21, 2024
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL )...Show more
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.Show less
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Mar 31, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.
1Theforeman
1Smart Proxy Salt
Nov 21, 2024
Mar 30, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated...Show more
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.Show less
1Google
1Android
Nov 21, 2024
Mar 30, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interact...Show more
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-186405146Show less
1Google
1Android
Nov 21, 2024
Mar 30, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f...Show more
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-203880906Show less