CWE-863
3,796 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,796)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A security misconfiguration exists in Combodo iTop, which can expose sensitive information. |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jul 31, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with a low-privileged account to bypass authorization on the API of an affected device. T...Show more |
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization, enabling them to access sensitive information, modify the syst...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Jul 29, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands. |
In "I hate money" before version 4.1.5, an authenticated member of one project can modify and delete members of another project, without knowledge of this other project's private code. This can be further exploited to ac...Show more |
1Parseplatform 1Parse Server Jun 17, 2026 Jul 22, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer...Show more |
In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in...Show more |
1Cisco 2Rv110w Firmware Rv215w FirmwareJun 17, 2026 Jul 16, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Small Business RV110W and RV215W Series Routers could allow an unauthenticated, remote attacker to download sensitive information from the device, which coul...Show more |
1Cisco 1Prime License Manager Jun 17, 2026 Jul 16, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web management interface of Cisco Prime License Manager (PLM) Software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to...Show more |
1Jenkins 1Gitlab Authentication Jun 17, 2026 Jul 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability. |
1Google 1Oauth Client Library For Java Jun 17, 2026 Jul 9, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client tha...Show more |
The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control. |
1Dell 5Emc Powerstore 1000 Firmware Emc Powerstore 3000 FirmwareEmc Powerstore 5000 Firmware+2 moreJun 17, 2026 Jul 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell EMC PowerStore versions prior to 1.0.1.0.5.002 contain a vulnerability that exposes test interface ports to external network. A remote unauthenticated attacker could potentially cause Denial of Service via test inte...Show more |
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced. |
In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of...Show more |
In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key. |
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions. |
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5 |
A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to reach the configured IP addre...Show more |
1Cisco 37Unified Ip Phone 6901 Firmware Unified Ip Phone 6911 FirmwareUnified Ip Phone 6921 Firmware+34 moreJun 17, 2026 Jun 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in the Web Access feature of Cisco IP Phones Series 7800 and Series 8800 could allow an unauthenticated, remote attacker to view sensitive information on an affected device. The vulnerability is due to im...Show more |