CWE-863
3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,796)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1M System 5Dl8 A Firmware Dl8 B FirmwareDl8 C Firmware+2 moreJun 17, 2026 Mar 18, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) versions prior to Ver3.0, type D (DL8-D) versions prior to Ver3.0, and type E (DL8-E) versions prior t...Show more |
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, w...Show more |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Mar 15, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Mar 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Mar 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17. |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Mar 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integrity and gain informat...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Mar 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the UMC authorization se...Show more |
3Dogtagpki FedoraprojectRedhat4Certificate System DogtagpkiEnterprise Linux+1 moreJun 17, 2026 Mar 15, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat...Show more |
The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this issue only affected the git master branch for a short time. Howe...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Mar 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login). |
2Elementary Fedoraproject2Fedora Switchboard Bluetooth PlugJun 17, 2026 Mar 12, 2021 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service...Show more |
In checkSlicePermission of SliceManagerService.java, there is a possible resource exposure due to an incorrect permission check. This could lead to local information disclosure with no additional execution privileges nee...Show more |
In checkUriPermission and related functions of MediaProvider.java, there is a possible way to access external files due to a permissions bypass. This could lead to local escalation of privilege with no additional executi...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in navigations in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. |
LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured to enable unauthenticated bind. |
The MigrationService, which is part of SAP NetWeaver versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform an authorization check. This might allow an unauthorized attacker to access configuration objects,...Show more |
2Elastic Oracle2Communications Cloud Native Core Automated Test Suite ElasticsearchJun 17, 2026 Mar 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Level Security is used. Get requests do not properly apply security permissions when executing a query a...Show more |
MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage service. In MinIO before version RELEASE.2021-03-04T00-53-13Z it is possible to bypass a readOnly poli...Show more |
Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All vers...Show more |