CWE-863
3,308 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the directory that the ap...Show more |
5Artifex DebianFedoraproject+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreJun 17, 2026 Sep 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted Po...Show more |
In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could lead to local escalation of privilege with no additional execution pri...Show more |
5Artifex DebianFedoraproject+2 more5Debian Linux FedoraGhostscript+2 moreJun 17, 2026 Sep 3, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially cra...Show more |
5Artifex DebianFedoraproject+2 more5Debian Linux FedoraGhostscript+2 moreJun 17, 2026 Sep 3, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafte...Show more |
2Kubernetes Redhat2Kubernetes Openshift Container PlatformJun 17, 2026 Aug 29, 2019 N/A· v4 8.1 HIGH· v3 6.5 MEDIUM· v2 The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced u...Show more |
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check. |
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check. |
1Microsoft 2Edge Internet ExplorerJun 17, 2026 Aug 14, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to...Show more |
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated. |
1Gcdwebserver Project 1Gcdwebserver Jun 17, 2026 Aug 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but not oldAbsolutePath. By leveraging this vulnerability, an adversary ca...Show more |
The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check. |
1Cisco 11Sf 220 24 Firmware Sf220 24p FirmwareSf220 48 Firmware+8 moreJun 17, 2026 Aug 7, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authoriz...Show more |
1Centos Webpanel 1Centos Web Panel Jun 17, 2026 Jul 26, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege. |
2Mozilla Opensuse2Firefox LeapJun 17, 2026 Jul 23, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potent...Show more |
Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unathorised access to data. The component is: Incorrect calls to _ensure_auth() wrapper result in authent...Show more |
1Huawei 3Honor Magic 2 Firmware Mate 20 FirmwareMate 20 X FirmwareJun 17, 2026 Jul 10, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Suc...Show more |
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL parameter in Mailvelope, an attacker is able to sign (and encrypt) arbitrary messages with Mailvelo...Show more |
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token (this is the parameter used by the API). No valid token is required since it is not validated by the...Show more |
In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the cdrom driver allows users wi...Show more |