CWE-863
3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,796)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Virginmedia 1Super Hub 3 Firmware Jun 17, 2026 Sep 20, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have insufficient protection mechanisms, it is possible to use JavaScript and DNS rebinding to leak the WAN...Show more |
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js. |
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page. |
2Envoyproxy Pomerium2Envoy PomeriumJun 17, 2026 Sep 9, 2021 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization related vulnerabilities CVE-2021-32777 and CVE-2021-32779. This may lead to incorrect routing or autho...Show more |
1Bab Technologie 1Eibport Firmware Jun 17, 2026 Sep 9, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. device serial number). Having those info, a possible loginId can be self-ca...Show more |
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later. |
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Authorization vulnerability in the customers module. Successful exploitation could allow a low-privile...Show more |
1Hitachiabb Powergrids 1Sdm600 Firmware Jun 17, 2026 Sep 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Da...Show more |
A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. . |
1Proofofdiligencetoken Project 1Proofofdiligencetoken Jun 17, 2026 Sep 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a reentrancy attack. |
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share. |
1Redux 1Gutenberg Template Library & Redux Framework Jun 17, 2026 Sep 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/cl...Show more |
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerabil...Show more |
1Adobe 2Adobe Commerce Magento Open SourceJun 17, 2026 Sep 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability via the `quoteId` parameter. An attacker can abuse this vulnerabili...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Aug 31, 2021 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Aug 31, 2021 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of th...Show more |
2Eclipse Fedoraproject2Fedora MosquittoJun 17, 2026 Aug 30, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions f...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Aug 27, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of...Show more |
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status |
Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics |