CWE-863
3,773 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,773)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Terra Master 1Terramaster Operating System Nov 21, 2024 Nov 27, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Incorrect access control on ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to elevate user permissions. |
1Buffalo 1Ts5600d1206 Firmware Nov 21, 2024 Nov 26, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Nov 16, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has...Show more |
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass via insecure direct object reference. |
Inova Partner 5.0.5-RELEASE, Build 0510-0906 and earlier allows authenticated users authorization bypass and data manipulation in certain functions. |
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no authorization delay, an attacker can be allowed to brute force account creden...Show more |
1Sonatype 1Nexus Repository Manager Nov 21, 2024 Nov 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control. |
VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users...Show more |
Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID boun...Show more |
1Huawei 1Emily Al00a Firmware Jun 17, 2026 Nov 13, 2018 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 The radio module of some Huawei smartphones Emily-AL00A The versions before 8.1.0.171(C00) have a lock-screen bypass vulnerability. An unauthenticated attacker could start third-part input method APP through certain oper...Show more |
In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of privilege, with System privileges needed. User interaction is not needed f...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreAug 29, 2025 Oct 25, 2018 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via ph...Show more |
2Canonical Mozilla2Firefox Ubuntu LinuxNov 25, 2025 Oct 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 a...Show more |
An issue was discovered in Joomla! before 3.8.13. Inadequate checks on the tags search fields can lead to an access level violation. |
4Canonical DebianParamiko+1 more11Ansible Tower Debian LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Oct 8, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity. |
A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to access sensitive informati...Show more |
1Cisco 1Network Functions Virtualization Infrastructure Nov 21, 2024 Oct 5, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient autho...Show more |
1Cisco 1Network Functions Virtualization Infrastructure Nov 21, 2024 Oct 5, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerab...Show more |
In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i...Show more |
1Dell 2Emc Unity Firmware Emc UnityvsaNov 21, 2024 Sep 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability. A remote authenticated user could potentially exploit this vulnerability to read files in NAS server by direc...Show more |