CWE-863
3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,796)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Insert Pages Project 1Insert Pages Jun 17, 2026 Nov 17, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcod...Show more |
Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admin...Show more |
1Binatoneglobal 21Cn28 Firmware Cn40 FirmwareCn50 Firmware+18 moreJun 17, 2026 Nov 12, 2021 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device. |
1Qualcomm 206Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+203 moreJun 17, 2026 Nov 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Co...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Nov 10, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, contains transport authorizations, which exceed...Show more |
1Commscope 1Arris Surfboard Sb8200 Firmware Jun 17, 2026 Nov 9, 2021 N/A· v4 7.1 HIGH· v3 4.9 MEDIUM· v2 The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password. |
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2). Applications built with affected versions of Mendix Studio...Show more |
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2). Applications built with affected versions of Mendix Studio...Show more |
1Batch Cat Project 1Batch Cat Jun 17, 2026 Nov 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are available for all roles. As a result, any authenticated user (including simple subscribers) can add/set/...Show more |
1Publishpress 1Post Expirator Jun 17, 2026 Nov 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts. |
1Vmware 1Spring Cloud Gateway Jun 17, 2026 Nov 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services. Users of affected versions should apply the following mitigation: 3.0.x use...Show more |
Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using `allowed_idp_claims` as part of poli...Show more |
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service. |
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4...Show more |
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident. |
When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. |
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/R...Show more |
1Stylishpricelist 1Stylish Price List Jun 17, 2026 Nov 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX action (available to authenticated users), which could allow any authenticated users, such as subscri...Show more |
1Stylishpricelist 1Stylish Price List Jun 17, 2026 Nov 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX action (available to both unauthenticated and authenticated users), which could allow unauthenticated...Show more |
1Radiustheme 1Logo Slider And Showcase Jun 17, 2026 Nov 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the rtWLSSettings AJAX action because it uses a nonce for authorisation instead of a capability check. |