CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 13 of 31
- CVE-2024-13646HIGHCVSS 8.1EG 8.12025-01-30
The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the 'single_user_chat_update_login' function in all versions up to, and inc…
- CVE-2024-13692MEDIUMCVSS 5.4EG 5.42025-02-14
The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.4.5 …
- CVE-2024-13694HIGHCVSS 7.5EG 7.52025-01-30
The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file()…
- CVE-2024-13724MEDIUMCVSS 4.3EG 4.32025-03-04
The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including, 2.6.2. This makes …
- CVE-2024-13821MEDIUMCVSS 5.3EG 5.32025-02-12
The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in all versions up to, and including, 10.10. This is due to the plugin not properly requiring re-verification after a book…
- CVE-2024-1741CRITICALCVSS 9.1EG 9.12024-04-10
lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these membe…
- CVE-2024-1803MEDIUMCVSS 4.3EG 4.32024-05-23
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient auth…
- CVE-2024-20333MEDIUMCVSS 4.3EG 4.32024-03-27
A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to change specific data within the interface on an affected device. This vulnerabil…
- CVE-2024-20381HIGHCVSS 8.8EG 8.82024-09-11
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers cou…
- CVE-2024-20393HIGHCVSS 8.8EG 8.82024-10-02
A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This …
- CVE-2024-20414MEDIUMCVSS 6.5EG 6.52024-09-25
A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI. This v…
- CVE-2024-20441MEDIUMCVSS 5.7EG 5.72024-10-02
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization co…
- CVE-2024-20497MEDIUMCVSS 4.3EG 4.32024-09-04
A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is due to inadequate authorization checks for Mobile and Remot…
- CVE-2024-20943MEDIUMCVSS 5.4EG 5.42024-02-17
Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker…
- CVE-2024-20979MEDIUMCVSS 5.4EG 5.42024-01-16
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0, 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker w…
- CVE-2024-21018MEDIUMCVSS 6.1EG 6.12024-04-16
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2024-21026MEDIUMCVSS 6.1EG 6.12024-04-16
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2024-21031MEDIUMCVSS 6.1EG 6.12024-04-16
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2024-21035MEDIUMCVSS 6.1EG 6.12024-04-16
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2024-21039MEDIUMCVSS 6.1EG 6.12024-04-16
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated at…
- CVE-2024-21137MEDIUMCVSS 4.9EG 4.92024-07-16
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior and 8.2.0 and prior. Easily exploitable vulnerability allows high privileged attacker wit…
- CVE-2024-21159MEDIUMCVSS 4.9EG 4.92024-07-16
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network a…
- CVE-2024-21166MEDIUMCVSS 5.9EG 5.92024-07-16
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network…
- CVE-2024-21179MEDIUMCVSS 4.9EG 4.92024-07-16
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.37 and prior and 8.4.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network a…
- CVE-2024-21402HIGHCVSS 7.1EG 7.12024-02-13
Microsoft Outlook Elevation of Privilege Vulnerability
- CVE-2024-21735HIGHCVSS 7.2EG 7.32024-01-09
SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This could allow an attacker with high privileges to perform unintended actions, r…
- CVE-2024-21736MEDIUMCVSS 6.5EG 6.52024-01-09
SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered allowing the attacker to create in-house bank accounts leading…
- CVE-2024-21761MEDIUMCVSS 4.3EG 4.32024-03-12
An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via modification in the request payload.
- CVE-2024-21987MEDIUMCVSS 5.4EG 5.42024-02-16
SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter Server user to modify system logging configuration settings
- CVE-2024-22021MEDIUMCVSS 4.3EG 6.52024-02-07
Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.
- CVE-2024-22388MEDIUMCVSS 5.9EG 5.92024-02-06
Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and device administration keys.
- CVE-2024-2317LOWCVSS 3.8EG 3.82024-03-08
A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affects some unknown processing of the file /prescription/prescription/delete/ of the component Prescription Page. The manipu…
- CVE-2024-23576HIGHCVSS 7.1EG 7.12024-05-14
Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.
- CVE-2024-23649HIGHCVSS 7.5EG 7.52024-01-24
Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, even when they're neither sender nor recipient of the message. The API response to creating …
- CVE-2024-23665MEDIUMCVSS 5.9EG 5.92024-06-03
Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, version 6.4.3 and below, version 6.3.23 and below may allow an authenticated attacker to perf…
- CVE-2024-23667HIGHCVSS 8.8EG 8.82024-06-03
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands vi…
- CVE-2024-23670HIGHCVSS 8.8EG 8.82024-06-03
An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands vi…
- CVE-2024-23806MEDIUMCVSS 5.3EG 5.32024-02-07
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
- CVE-2024-2441HIGHCVSS 8.1EG 8.12024-05-14
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel …
- CVE-2024-24830CRITICALCVSS 9.9EG 9.92024-02-08
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any a…
- CVE-2024-24900MEDIUMCVSS 5.8EG 5.82024-03-01
Dell Secure Connect Gateway (SCG) Policy Manager, all versions, contain an improper authorization vulnerability. An adjacent network low privileged attacker could potentially exploit this vulnerability, leading to unauthorized devices adde…
- CVE-2024-24936MEDIUMCVSS 4.3EG 4.32024-02-06
In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed
- CVE-2024-25063HIGHCVSS 7.5EG 7.52024-03-02
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.
- CVE-2024-25106CRITICALCVSS 9.1EG 9.12024-02-08
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulner…
- CVE-2024-25108CRITICALCVSS 9.9EG 9.92024-02-12
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative a…
- CVE-2024-2557MEDIUMCVSS 5.3EG 5.32024-03-17
A vulnerability was found in kishor-23 Food Waste Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/admin.php. The manipulation leads to improper authorization. The attack c…
- CVE-2024-25949HIGHCVSS 8.8EG 8.82024-06-12
Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authenticated attacker could potentially exploit this vulnerability leading to escalation of privil…
- CVE-2024-26193MEDIUMCVSS 6.4EG 6.42024-04-09
Azure Migrate Remote Code Execution Vulnerability
- CVE-2024-26291HIGHCVSS 8.7EG 8.72025-07-14
An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest priv…
- CVE-2024-2641MEDIUMCVSS 5.3EG 5.32024-03-19
A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been classified as critical. Affected is an unknown function of the file /system/passwdManage.htm of the component Password Handler. The manipulation leads to imprope…
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →