CWE-863
3,308 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Mar 12, 2017 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality. |
An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login screen to access local...Show more |
1Cisco 1Unified Computing System Director May 13, 2026 Feb 15, 2017 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary workflow items with just an end-user profile, a Privilege Escalation Vulner...Show more |
1Adobe 2Flash Player Flash Player Desktop RuntimeMay 6, 2026 Jul 13, 2016 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information v...Show more |
Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local proxy. |
6Canonical CitrixDebian+3 more8Debian Linux FedoraLinux Enterprise Desktop+5 moreMay 6, 2026 Jun 3, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensiti...Show more |
4Apache CanonicalFedoraproject+1 more4Enterprise Manager Ops Center FedoraHttp Server+1 moreMay 6, 2026 Dec 29, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within differ...Show more |
OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the...Show more |
1Siemens 1Ruggedcom Rugged Operating System Apr 29, 2026 Dec 17, 2013 N/A· v4 N/A· v3 8.0 HIGH· v2 The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account. |
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user...Show more |
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for rem...Show more |
1Cisco 1Carrier Routing System Apr 29, 2026 Aug 6, 2012 N/A· v4 5.8 MEDIUM· v3 5.0 MEDIUM· v2 Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975. |
The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect 11.4.0.2, 11.4.0.1, and earlier, does not properly restrict the SetLay...Show more |
Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack vectors. |
vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not...Show more |
2Rockwellautomation Windriver21756 Enbt/a Firmware VxworksMay 28, 2026 Aug 5, 2010 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or m...Show more |
1Kyoceramita 1Scanner File Utility Apr 23, 2026 Aug 28, 2009 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified program that does not prompt the user fo...Show more |
1Citrix 2Netscaler Access Gateway Netscaler Access Gateway FirmwareApr 23, 2026 Jun 25, 2009 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action optio...Show more |
4Net Snmp OpensuseRedhat+1 more4Enterprise Linux Linux EnterpriseNet Snmp+1 moreApr 23, 2026 Feb 12, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to...Show more |
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to lever...Show more |