CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 12 of 31
- CVE-2023-44123HIGHCVSS 7.8EG 7.82023-09-27
The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Bluetooth ("com.lge.bluetoothsetting") app. The attacke…
- CVE-2023-44125HIGHCVSS 7.8EG 7.82023-09-27
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE set that leads to theft and/or (over-)write of arbitrary files with system privilege in the Personalized service ("com.lge.abba") app. The att…
- CVE-2023-44154HIGHCVSS 8.1EG 8.12023-09-27
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
- CVE-2023-44410HIGHCVSS 8.8EG 8.82024-05-03
D-Link D-View showUsers Improper Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of D-Link D-View. Authentication is required to exploit this vul…
- CVE-2023-47109HIGHCVSS 8.1EG 8.12023-11-08
PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassurance module, a BO user can modify the http request and give…
- CVE-2023-47166HIGHCVSS 8.8EG 8.82024-05-01
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger …
- CVE-2023-48241HIGHCVSS 7.5EG 8.72023-11-20
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results…
- CVE-2023-48252HIGHCVSS 8.8EG 8.82024-01-10
The vulnerability allows an authenticated remote attacker to perform actions exceeding their authorized access via crafted HTTP requests.
- CVE-2023-48309MEDIUMCVSS 5.3EG 5.32023-11-20
NextAuth.js provides authentication for Next.js. `next-auth` applications prior to version 4.24.5 that rely on the default Middleware authorization are affected by a vulnerability. A bad actor could create an empty/mock user, by getting ho…
- CVE-2023-50363HIGHCVSS 7.4EG 7.42024-04-26
An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. We have alr…
- CVE-2023-5061MEDIUMCVSS 4.3EG 4.32023-12-15
An issue has been discovered in GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. In certain situations, it may have been possible f…
- CVE-2023-50780HIGHCVSS 8.8EG 8.82024-10-14
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not m…
- CVE-2023-50871MEDIUMCVSS 4.3EG 4.32023-12-15
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
- CVE-2023-52139CRITICALCVSS 9.6EG 9.62023-12-29
Misskey is an open source, decentralized social media platform. Third-party applications may be able to access some endpoints or Websocket APIs that are incorrectly specified as [kind](https://github.com/misskey-dev/misskey/blob/406b4bdbe7…
- CVE-2023-52359HIGHCVSS 7.5EG 7.52024-04-08
Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-52539HIGHCVSS 7.5EG 7.52024-04-08
Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2023-53895CRITICALCVSS 9.8EG 9.82025-12-16
PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to create admin accounts without authorization through the configuration endpoint. Attackers can exploit the unsanitized username field to inje…
- CVE-2023-5654MEDIUMCVSS 6.5EG 6.52023-10-19
The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requ…
- CVE-2023-5675MEDIUMCVSS 6.5EG 6.52024-04-25
A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions using the annotation processor, the authorization of these met…
- CVE-2023-5808HIGHCVSS 6.5EG 8.82023-12-05
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that …
- CVE-2023-5948HIGHCVSS 5.5EG 8.22023-11-03
Improper Authorization in GitHub repository teamamaze/amazefileutilities prior to 1.91.
- CVE-2023-6496MEDIUMCVSS 5.3EG 5.32024-01-11
The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthenticated attackers to ob…
- CVE-2023-6538HIGHCVSS 6.5EG 7.62023-12-11
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in Storage, Server or combined Server+Storage administrative roles are able to access SMU configuration …
- CVE-2023-6564MEDIUMCVSS 6.5EG 6.52024-02-08
An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which sub…
- CVE-2023-6731MEDIUMCVSS 4.3EG 4.32024-05-02
The WP Show Posts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 1.1.5. This makes it possible for authenticated attacker…
- CVE-2023-6878HIGHCVSS 8.8EG 8.82024-01-11
The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcssb_ajax_update' function in versions up to, and including, 2.4.11. This makes it possible f…
- CVE-2024-0077HIGHCVSS 7.8EG 7.82024-03-27
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, where it allows a guest OS to allocate resources for which the guest OS is not authorized. A successful exploit of this vulnerability may lead to code execution, denia…
- CVE-2024-0456MEDIUMCVSS 4.3EG 4.32024-01-26
An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project
- CVE-2024-0861MEDIUMCVSS 4.3EG 4.32024-02-22
An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom…
- CVE-2024-0870MEDIUMCVSS 5.3EG 5.32024-05-14
The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_mail_status' and 'save_email_settings' functions in all versions up to, and including, 4…
- CVE-2024-10274MEDIUMCVSS 6.5EG 6.52025-03-20
An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequate access control mechanisms, allowing unauthorized users to access sensitive information about all team members in th…
- CVE-2024-1043MEDIUMCVSS 6.5EG 6.52024-02-29
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'amppb_remove_saved_layout_data' function in all versions up to, and including, 1.0.93.1. …
- CVE-2024-10598MEDIUMCVSS 5.3EG 5.32024-10-31
A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave Handler. The manipulatio…
- CVE-2024-10654MEDIUMCVSS 5.3EG 5.32024-11-01
A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /formLoginAuth.htm. The manipulation of the argument authCode with the in…
- CVE-2024-10729HIGHCVSS 8.8EG 8.82024-11-26
The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_google_calendar_data' function in versions up to, and including, 6.9.0.…
- CVE-2024-11073MEDIUMCVSS 4.3EG 4.32024-11-11
A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /vm/patient/delete-account.php. The manipulation of the argument id leads to improper autho…
- CVE-2024-11306MEDIUMCVSS 5.3EG 5.32024-11-18
A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of the file /index.php/display/database/. The manipulation leads to improper a…
- CVE-2024-11768MEDIUMCVSS 5.3EG 5.32024-12-19
The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all versions up to, and including, 3.3.03. This makes i…
- CVE-2024-11860MEDIUMCVSS 6.5EG 6.52024-11-27
A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects an unknown part of the file /rental/ajax.php?action=delete_tenant of the component POST Request Handler. The mani…
- CVE-2024-12347MEDIUMCVSS 5.3EG 5.32024-12-09
A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown processing of the file /jeewms_war/webpage/system/druid/index.html of the component Druid Mo…
- CVE-2024-12483LOWCVSS 3.7EG 3.72024-12-12
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to i…
- CVE-2024-12782HIGHCVSS 7.3EG 7.32024-12-19
A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the componen…
- CVE-2024-12880HIGHCVSS 6.5EG 8.12025-03-20
A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from the way tenant IDs are handled in the application. If a user has access to multiple tenants,…
- CVE-2024-1289MEDIUMCVSS 6.5EG 6.52024-04-09
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.6.3 due to missing validation on a user controlled key when looking up order informati…
- CVE-2024-12901MEDIUMCVSS 5.3EG 5.32024-12-23
A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the component API Endpoint. The manipulation of the argument passw…
- CVE-2024-13058MEDIUMCVSS 4.8EG 4.82024-12-30
An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could potentially impact the performance and availability of the backend software-defined storage subsystem. This issue only imp…
- CVE-2024-13060MEDIUMCVSS 4.3EG 4.32025-03-20
A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1.
- CVE-2024-13109MEDIUMCVSS 5.3EG 5.32025-01-02
A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper a…
- CVE-2024-13241CRITICALCVSS 9.1EG 9.12025-01-09
Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5.
- CVE-2024-13552MEDIUMCVSS 4.3EG 4.32025-03-07
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due to missing validation on a user controlle…
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →