CWE-863
2,984 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (2,984)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr...Show more |
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to acce...Show more |
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the ca...Show more |
In AudioService, there is a possible trigger of background user audio due to a permissions bypass. This could lead to local information disclosure by playing the background user's audio with no additional execution privi...Show more |
In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to determine device location with no additional execution privileges need...Show more |
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability...Show more |
2Debian Lemonldap Ng2Debian Linux Lemonldap\May 28, 2025 Sep 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party...Show more |
A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device....Show more |
6Canonical DockerFedoraproject+3 more10Docker Enterprise LinuxEnterprise Linux Eus+7 moreNov 21, 2024 Sep 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image...Show more |
The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak. |
1Schneider Electric 4Meg6260 0410 Firmware Meg6260 0415 FirmwareMeg6501 0001 Firmware+1 moreNov 21, 2024 Sep 17, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U...Show more |
1Schneider Electric 4Meg6260 0410 Firmware Meg6260 0415 FirmwareMeg6501 0001 Firmware+1 moreNov 21, 2024 Sep 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U...Show more |
An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request. |
1Nxp 3Kinetis K8x Firmware Kinetis Kv1x FirmwareKinetis Kv3x FirmwareNov 21, 2024 Sep 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruct...Show more |
1St 6Stm32f4 Firmware Stm32f7 FirmwareStm32h7 Firmware+3 moreNov 21, 2024 Sep 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated by observing CPU registers and the ef...Show more |
1Microsoft 3Windows 10 Windows Server 2016Windows Server 2019Nov 21, 2024 Sep 11, 2019 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerabilit...Show more |
The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is valid via a missing permissions check. |
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the ap...Show more |
5Artifex DebianFedoraproject+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreNov 21, 2024 Sep 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted Po...Show more |
In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could lead to local escalation of privilege with no additional execution pri...Show more |