CWE-863
3,780 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,780)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Icegram 1Email Subscribers & Newsletters Jun 17, 2026 Dec 26, 2019 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns. |
1Fermax 1Outdoor Panel Firmware Nov 21, 2024 Dec 24, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a res...Show more |
2Apple Debian2Cups Debian LinuxNov 21, 2024 Dec 20, 2019 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system |
1Cloudfoundry 2Capi Release Cf DeploymentJun 17, 2026 Dec 19, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins. |
This issue was addressed with improved transparency. This issue is fixed in iOS 12.2. A user may authorize an enterprise administrator to remotely wipe their device without appropriate disclosure. |
1Sap 2Enterprise Extension Financial Services Treasury And Risk Management (s4core)Jun 17, 2026 Dec 17, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary autho...Show more |
1Sap 2Enterprise Extension Financial Services Treasury And Risk Management (s4core)Jun 17, 2026 Dec 17, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary autho...Show more |
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions. |
D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header. |
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen. |
2Fedoraproject Reviewboard2Fedora ReviewboardNov 21, 2024 Dec 3, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Review Board: URL processing gives unauthorized users access to review lists |
2Fedoraproject Reviewboard2Fedora ReviewboardNov 21, 2024 Dec 2, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ReviewBoard: has an access-control problem in REST API |
Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass Sentry document-level security via the RealTimeGetHandler. |
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges. |
Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls. |
2Debian Tahoe Lafs2Debian Linux Tahoe LafsNov 21, 2024 Nov 26, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases. |
Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension. |
Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. |
2Google Opensuse2Backports Sle ChromeJun 17, 2026 Nov 25, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
1Redhat 2Ovirt Engine VirtualizationNov 21, 2024 Nov 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center |