CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 16 of 31
- CVE-2024-6384MEDIUMCVSS 5.3EG 5.32024-08-13
"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions…
- CVE-2024-6840MEDIUMCVSS 6.6EG 6.62024-09-12
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, result…
- CVE-2024-7015CRITICALCVSS 9.8EG 9.82024-09-09
Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue affects PassBox: before v1.2.
- CVE-2024-7578HIGHCVSS 7.3EG 7.32024-08-07
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the file /var/www/cmd.php. The manipulation of the argument cmd leads to improper authorizatio…
- CVE-2024-7624HIGHCVSS 8.1EG 8.12024-08-15
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enabl…
- CVE-2024-7799MEDIUMCVSS 5.3EG 5.32024-08-15
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /simple-online-bidding-system/bidding/admin/users.php. The manipu…
- CVE-2024-7851MEDIUMCVSS 6.3EG 6.32024-08-16
A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Users.php?f=save of the component Add User Handler. The manipulati…
- CVE-2024-8181CRITICALCVSS 9.8EG 9.82024-08-27
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
- CVE-2024-8509HIGHCVSS 7.5EG 7.52024-09-06
A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some form of a Bearer token, a 401 error occu…
- CVE-2024-8676HIGHCVSS 7.4EG 7.42024-11-26
A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead o…
- CVE-2024-8764HIGHCVSS 7.5EG 7.52025-03-20
A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressions on the server side. This can lead to a Denial of Service (DoS) condition, as certain regular expressions can cause …
- CVE-2024-9000HIGHCVSS 6.5EG 7.12025-03-20
In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the user has proper permissions. This missing access control permits unauthorized users to cre…
- CVE-2024-9082MEDIUMCVSS 6.3EG 6.32024-09-22
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save of the component User Creation Handler. The mani…
- CVE-2024-9095CRITICALCVSS 9.8EG 9.82025-03-20
In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export the entire database. This includes sensitive data such as password h…
- CVE-2024-9096HIGHCVSS 7.1EG 7.62025-03-20
In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending a PATCH request. The route lacks proper access control, such as middleware to ensure that only authorized users (e.g.,…
- CVE-2024-9235HIGHCVSS 8.8EG 8.82024-10-25
The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability check on the mapster_wp_maps_set_option_from_js() function in all versions …
- CVE-2024-9297MEDIUMCVSS 6.3EG 6.32024-09-28
A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument page with…
- CVE-2024-9531MEDIUMCVSS 4.3EG 4.32024-10-24
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mvx_sent_deactivation_request' function in all…
- CVE-2025-0484HIGHCVSS 7.3EG 7.32025-01-15
A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical. This issue affects some unknown processing of the file /fladmin/sysconfig_doedit.php of the component Backend. The manipulation leads to improper authori…
- CVE-2025-0580MEDIUMCVSS 5.6EG 5.62025-01-20
A vulnerability was found in Shiprocket Module 3 on OpenCart. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php?route=extension/module/rest_api&action=getOrders of the component REST…
- CVE-2025-0849MEDIUMCVSS 6.3EG 6.32025-01-30
A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the component Staff Handler. The manipulation leads to improper authorization. I…
- CVE-2025-0928HIGHCVSS 8.8EG 8.82025-07-08
In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent binaries to any model or to the controller itself, without verifying model membership or requiring explicit permissions. Th…
- CVE-2025-10014LOWCVSS 3.1EG 3.12025-09-05
A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component Email Address Handler. Executing manipulation of the argument id/email can lead to improper a…
- CVE-2025-1007MEDIUMCVSS 5.3EG 5.32025-02-19
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, su…
- CVE-2025-10073MEDIUMCVSS 4.3EG 4.32025-09-08
A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Api/turma. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The e…
- CVE-2025-10084MEDIUMCVSS 4.3EG 4.32025-09-08
A vulnerability was identified in elunez eladmin up to 2.7. This affects the function queryErrorLogDetail of the file /api/logs/error/1 of the component SysLogController. The manipulation leads to improper authorization. It is possible to …
- CVE-2025-10086MEDIUMCVSS 6.3EG 6.32025-09-08
A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionController. This manipulation causes improper authorization. The attack…
- CVE-2025-10209MEDIUMCVSS 5.4EG 5.42025-09-10
A security flaw has been discovered in Papermerge DMS up to 3.5.3. This issue affects some unknown processing of the component Authorization Token Handler. Performing manipulation results in improper authorization. The attack can be initia…
- CVE-2025-10275MEDIUMCVSS 6.3EG 6.32025-09-12
A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Executing manipulation of the argument ids/newOwnerUserId can lead to improper authorization. The attack m…
- CVE-2025-10276MEDIUMCVSS 6.3EG 6.32025-09-12
A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the argument id/newOwnerUserId leads to improper authorizatio…
- CVE-2025-10277MEDIUMCVSS 6.3EG 6.32025-09-12
A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file /crm/receivable/submit. The manipulation of the argument ID results in improper authorization. The attack can be execu…
- CVE-2025-10278MEDIUMCVSS 6.3EG 6.32025-09-12
A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument ids/newOwnerUserId causes improper authorization. The attack is possible to b…
- CVE-2025-10291MEDIUMCVSS 6.3EG 6.32025-09-12
A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. Executing manipulation of the argument ID can lead to improper authorization. The attack c…
- CVE-2025-10318MEDIUMCVSS 6.3EG 6.32025-09-12
A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler. The manipulation of the argument userI…
- CVE-2025-10319MEDIUMCVSS 4.3EG 4.32025-09-12
A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Export. The manipulation results in improper authorization. Th…
- CVE-2025-10374HIGHCVSS 7.3EG 7.32025-09-13
A security flaw has been discovered in Shenzhen Sixun Business Management System 7/11. This affects an unknown part of the file /Adm/OperatorStop. Performing manipulation results in improper authorization. The attack is possible to be carr…
- CVE-2025-10384MEDIUMCVSS 5.4EG 5.42025-09-13
A flaw has been found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/cancelAll of the component Role Handler. Executing manipulation of the argument roleId/u…
- CVE-2025-10389MEDIUMCVSS 5.4EG 5.42025-09-14
A security flaw has been discovered in CRMEB up to 5.6.1. Impacted is the function Save of the file app/services/system/admin/SystemAdminServices.php of the component Administrator Password Handler. Performing manipulation of the argument …
- CVE-2025-10390MEDIUMCVSS 5.4EG 5.42025-09-14
A weakness has been identified in CRMEB up to 5.6.1. The affected element is the function editAddress of the file app/services/user/UserAddressServices.php. Executing manipulation of the argument ID can lead to improper authorization. The …
- CVE-2025-10422MEDIUMCVSS 4.3EG 4.32025-09-15
A vulnerability has been found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. This issue affects the function paySuccess of the file /paySuccess of the component Order Status Handler. The manipulation of the argument orderN…
- CVE-2025-10674MEDIUMCVSS 4.3EG 4.32025-09-18
A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController of the file /attributecategory/queryAll. Such manipulation leads to improper authorization. The attack may be launched r…
- CVE-2025-10675MEDIUMCVSS 4.3EG 4.32025-09-18
A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of the file /attribute/queryAll. Performing manipulation results in improper authorization. Remote exploitation of the atta…
- CVE-2025-10676MEDIUMCVSS 4.3EG 4.32025-09-18
A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /brand/queryAll. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The expl…
- CVE-2025-10707MEDIUMCVSS 6.3EG 6.32025-09-19
A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper authorization. The attack may be launched remotely. The e…
- CVE-2025-10731MEDIUMCVSS 5.3EG 5.32026-03-23
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the allRe…
- CVE-2025-10736MEDIUMCVSS 6.5EG 6.52026-03-23
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to unauthorized access of data due to improper authorization checks on the userAccessibility…
- CVE-2025-10759MEDIUMCVSS 5.3EG 5.32025-09-21
A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated re…
- CVE-2025-1078MEDIUMCVSS 5.3EG 5.32025-02-06
A vulnerability has been found in AppHouseKitchen AlDente Charge Limiter up to 1.29 on macOS and classified as critical. This vulnerability affects the function shouldAcceptNewConnection of the file com.apphousekitchen.aldente-pro.helper o…
- CVE-2025-10819MEDIUMCVSS 4.3EG 4.32025-09-22
A security vulnerability has been detected in fuyang_lipengjun platform 1.0. This issue affects the function UserCouponController of the file /usercoupon/queryAll. The manipulation leads to improper authorization. Remote exploitation of th…
- CVE-2025-10820MEDIUMCVSS 4.3EG 4.32025-09-22
A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /topic/queryAll. The manipulation results in improper authorization. The attack can be executed remotely. The exploit is no…
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →