CWE-863
3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,796)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attackers to gain admin access to site instances, even if they do not possess an existing account. This vuln...Show more |
An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a c...Show more |
1Hide Thread Content Project 1Hide Thread Content Jun 17, 2026 Jan 28, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit. |
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token. |
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image. |
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image. |
2Apache Oracle3Financial Services Crime And Compliance Management Studio HadoopSolrJun 17, 2026 Jan 26, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification. |
1Cisco 4Ios Xe Sd Wan Sd Wan FirmwareSd Wan Vbond Orchestrator+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, ga...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 20, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 20, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For...Show more |
IBM Planning Analytics 2.0 could allow an attacker to obtain sensitive information due to an overly permissive CORS policy. IBM X-Force ID: 190836. |
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sens...Show more |
1Cisco 1Connected Mobile Experiences Jun 17, 2026 Jan 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow a remote, authenticated attacker without administrative privileges to alter the password of any user on an affected system. The vulnerability is due...Show more |
1Cisco 1Connected Mobile Experiences Jun 17, 2026 Jan 13, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in Cisco Connected Mobile Experiences (CMX) API authorizations could allow an authenticated, remote attacker to enumerate what users exist on the system. The vulnerability is due to a lack of authorizatio...Show more |
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did hav...Show more |
In checkCallerIsSystemOr of CompanionDeviceManagerService.java, there is a possible way to get a nearby Bluetooth device's MAC address without appropriate permissions due to a permissions bypass. This could lead to local...Show more |
In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User i...Show more |
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreJul 9, 2026 Jan 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: gain privileges (local). The component is: K7TSMngr.exe. |
1K7computing 4Antivrius Enterprise SecurityTotal Security+1 moreJul 9, 2026 Jan 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control. The impact is: Local Process Execution (local). The component is: K7Sentry.sys. |
NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorizat...Show more |