CWE-863
3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,796)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary...Show more |
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. A vulnerability in the AirWave web-based management interface could allow an aut...Show more |
A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to access files in other directories by performing specific operations, resulting in information leak....Show more |
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the category for an article. |
1Dataiku 1Data Science Studio Jun 17, 2026 Mar 1, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have coding permissions) to read and overwrite notebooks in projects that they are not authorized to access. |
1Synology 4Diskstation Manager Diskstation Manager Unified ControllerSkynas Firmware+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Incorrect authorization vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vectors. |
3Fedoraproject PostgresqlRedhat4Enterprise Linux FedoraPostgresql+1 moreJun 17, 2026 Feb 23, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerabili...Show more |
1Vmware 1Spring Cloud Netflix Zuul Jun 17, 2026 Feb 23, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially cons...Show more |
1Visualware 1Myconnection Server Jun 17, 2026 Feb 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access code. |
Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure. |
Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast before version 9.2 there is a vulnerability in which publishing an episode with strict access rules w...Show more |
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system w...Show more |
2Podman Project Redhat3Enterprise Linux Openshift Container PlatformPodmanJun 17, 2026 Feb 11, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access an...Show more |
1Fiberhome 1Hg6245d Firmware Jun 17, 2026 Feb 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on FiberHome HG6245D devices through RP2613. It is possible to bypass authentication by sending the decoded value of the GgpoZWxwCmxpc3QKd2hvCg== string to the telnet server. |
Electric Coin Company Zcashd before 2.1.1-1 allows attackers to trigger consensus failure and double spending. A valid chain could be incorrectly rejected because timestamp requirements on block headers were not properly...Show more |
1Netgear 19Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+16 moreJun 17, 2026 Feb 4, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR R7450 1.2.0.62_1.0.1 routers. Authentication is not required to exploit this vulnerability. The...Show more |
In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly. |
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user. |
An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the rcp client only pe...Show more |
AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. In AVideo Platform before version 10.2 there is an authorization bypass vulnerability which enables an ordinary user to...Show more |