CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 14 of 31
- CVE-2024-27916HIGHCVSS 7.1EG 7.12024-03-21
Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRepositoryByName`, `DeleteRepositoryByName`, and `GetArtifactByName` to access any repository in the database, irrespecti…
- CVE-2024-27930MEDIUMCVSS 6.5EG 6.52024-03-18
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. Thi…
- CVE-2024-27937MEDIUMCVSS 6.5EG 6.52024-03-18
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can obtain the email address of all GLPI users. This issue has been patched …
- CVE-2024-28029HIGHCVSS 8.8EG 8.82024-03-21
Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.
- CVE-2024-28285CRITICALCVSS 9.8EG 9.82024-05-14
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.
- CVE-2024-29033HIGHCVSS 7.5EG 7.52024-03-20
OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any OAuth 2.0 provider. `GoogleOAuthenticator.hosted_domain` is used to restrict what Google ac…
- CVE-2024-30061HIGHCVSS 7.3EG 7.32024-07-09
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
- CVE-2024-3013MEDIUMCVSS 6.3EG 6.32024-03-28
A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools/test_login.php?action=register of the component User Registration. Executing manipulation can lead to improper authori…
- CVE-2024-30260LOWCVSS 3.9EG 3.92024-04-04
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 …
- CVE-2024-3027MEDIUMCVSS 6.4EG 6.42024-04-13
The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in all versions up to, and including, 3.5.1.22. This makes it possible for authenticated at…
- CVE-2024-3033CRITICALCVSS 9.4EG 9.42024-06-06
An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the Vecto…
- CVE-2024-3139MEDIUMCVSS 5.4EG 5.42024-04-01
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function save_users of the file /classes/Users.php?f=save. The manipulation of the…
- CVE-2024-31409MEDIUMCVSS 6.5EG 6.52024-05-15
Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.
- CVE-2024-32359MEDIUMCVSS 6.9EG 6.92024-05-02
An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through designed commands to obtain the secrets of the entire cluster and further take over the cluster.
- CVE-2024-3269MEDIUMCVSS 5.4EG 5.42024-05-30
The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for…
- CVE-2024-32881CRITICALCVSS 9.8EG 9.82024-04-26
Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full c…
- CVE-2024-33749CRITICALCVSS 9.1EG 9.12024-05-06
DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
- CVE-2024-34104HIGHCVSS 8.2EG 8.22024-06-13
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass securit…
- CVE-2024-34257CRITICALCVSS 9.8EG 9.82024-05-08
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.
- CVE-2024-3434MEDIUMCVSS 5.4EG 5.42024-04-08
A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability is an unknown functionality of the component User Management. The manipulation leads to improper authorization. The att…
- CVE-2024-34463MEDIUMCVSS 5.1EG 5.12024-09-03
BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.)
- CVE-2024-36108CRITICALCVSS 9.8EG 9.82024-05-31
casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sensitive information via GET request to an API endpoint. This issue has been addressed in PR …
- CVE-2024-36130CRITICALCVSS 9.8EG 9.82024-08-07
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
- CVE-2024-36399HIGHCVSS 8.2EG 8.22024-06-06
Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL pa…
- CVE-2024-36438HIGHCVSS 7.3EG 7.32024-07-15
eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other attacks.
- CVE-2024-36467HIGHCVSS 7.5EG 7.52024-11-27
An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to gr…
- CVE-2024-37154MEDIUMCVSS 5.3EG 5.32024-06-06
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects employees and grantees who have funds managed via `ClawbackVestingAccount`. This affects 1…
- CVE-2024-37159LOWCVSS 3.5EG 3.52024-06-17
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a validator using vested tokens to deposit the self-bond. This vulnerability is fixed in 18.0.0.
- CVE-2024-37167MEDIUMCVSS 4.3EG 4.32024-06-25
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not see. This issue has been patched in Tuleap Community Edition version 15.9.99.97.
- CVE-2024-37282CRITICALCVSS 8.1EG 9.82024-06-28
It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create new API keys that have elevated privileges.
- CVE-2024-38129HIGHCVSS 7.5EG 7.52024-10-08
Windows Kerberos Elevation of Privilege Vulnerability
- CVE-2024-38231MEDIUMCVSS 6.5EG 6.52024-09-10
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
- CVE-2024-38329HIGHCVSS 7.7EG 7.72024-06-19
IBM Storage Protect for Virtual Environments: Data Protection for VMware 8.1.0.0 through 8.1.22.0 could allow a remote authenticated attacker to bypass security restrictions, caused by improper validation of user permission. By sending a s…
- CVE-2024-38370MEDIUMCVSS 5.3EG 5.32024-11-15
GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to download a document from the API without appropriate rights. Upgrade to 10.0.16.
- CVE-2024-38371HIGHCVSS 8.6EG 8.62024-06-28
authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens…
- CVE-2024-3840HIGHCVSS 7.5EG 7.52024-04-17
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2024-38425MEDIUMCVSS 6.1EG 6.12024-10-07
Information disclosure while sending implicit broadcast containing APP launch information.
- CVE-2024-39404MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39405MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39407MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39411MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39412MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39413MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39415MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39416MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39417MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39418MEDIUMCVSS 5.4EG 5.42024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-39419MEDIUMCVSS 4.3EG 4.32024-08-14
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability …
- CVE-2024-3959MEDIUMCVSS 6.5EG 6.52024-06-27
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.
- CVE-2024-39597HIGHCVSS 7.2EG 7.22024-07-09
In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and registration is activated, without requiring the merchant to approve the account beforehan…
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →