CWE-285— Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.— MITRE CWE catalog
1,506 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-285page 9 of 31
- CVE-2022-39890HIGHCVSS 6.2EG 7.52022-11-09
Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.
- CVE-2022-39902HIGHCVSS 6.5EG 7.52022-12-08
Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.
- CVE-2022-39905MEDIUMCVSS 4.0EG 5.52022-12-08
Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.
- CVE-2022-40208MEDIUMCVSS 4.3EG 4.32023-03-24
In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigation during a quiz attempt.
- CVE-2022-40521HIGHCVSS 7.5EG 7.52023-06-06
Transient DOS due to improper authorization in Modem
- CVE-2022-40536HIGHCVSS 7.5EG 7.52023-06-06
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network.
- CVE-2022-4062HIGHCVSS 7.8EG 7.82023-02-01
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission application. Affected Product…
- CVE-2022-41610MEDIUMCVSS 5.0EG 5.02023-05-10
Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-4281HIGHCVSS 6.3EG 8.82022-12-05
A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /face-recognition-php/facepay-master/camera.php. The manipulation of the argument userId leads…
- CVE-2022-42961MEDIUMCVSS 5.3EG 5.32022-10-15
An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC keys, such as in server-side TLS connections, might leak fau…
- CVE-2022-43465MEDIUMCVSS 5.0EG 5.02023-05-10
Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-45128MEDIUMCVSS 5.0EG 5.02023-05-10
Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2022-45450HIGHCVSS 7.5EG 7.52023-05-18
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 3…
- CVE-2022-45874MEDIUMCVSS 5.5EG 5.52022-12-28
Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit could allow the attacker to access certain file.
- CVE-2022-4613MEDIUMCVSS 5.0EG 6.52022-12-19
A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects some unknown processing of the component Browser Extension Provisioning. The manipulation le…
- CVE-2022-46312HIGHCVSS 7.5EG 7.52022-12-20
The application management module has a vulnerability in permission verification. Successful exploitation of this vulnerability causes unexpected clear of device applications.
- CVE-2022-46752MEDIUMCVSS 4.6EG 4.62023-03-08
Dell BIOS contains an Improper Authorization vulnerability. An unauthenticated physical attacker may potentially exploit this vulnerability, leading to denial of service.
- CVE-2022-4688HIGHCVSS 8.8EG 8.82022-12-23
Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.
- CVE-2022-4701HIGHCVSS 4.3EG 8.82023-01-10
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those w…
- CVE-2022-47409CRITICALCVSS 9.1EG 9.12022-12-14
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of mo…
- CVE-2022-47553HIGHCVSS 8.6EG 8.62023-09-19
Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive information for the organisation, without being authenticated within the web server.
- CVE-2022-4804MEDIUMCVSS 5.3EG 5.32022-12-28
Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.
- CVE-2022-4868MEDIUMCVSS 4.3EG 4.32022-12-31
Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
- CVE-2022-4879HIGHCVSS 4.6EG 7.52023-01-06
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. …
- CVE-2022-4962MEDIUMCVSS 4.3EG 4.32024-01-12
A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the component Configuration Center. The manipulation leads to improper authorization.…
- CVE-2023-0456HIGHCVSS 7.4EG 7.42023-09-27
A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This could allow a separate realm to be accessible to an attacker, permitting access to unauthorize…
- CVE-2023-0583MEDIUMCVSS 4.3EG 4.32023-06-03
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions…
- CVE-2023-0584MEDIUMCVSS 4.3EG 4.32023-06-03
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above,…
- CVE-2023-0609MEDIUMCVSS 4.3EG 4.32023-02-01
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
- CVE-2023-0610MEDIUMCVSS 4.3EG 4.32023-02-01
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
- CVE-2023-0665MEDIUMCVSS 6.5EG 6.52023-03-30
HashiCorp Vault's PKI mount issuer endpoints did not correctly authorize access to remove an issuer or modify issuer metadata, potentially resulting in denial of service of the PKI mount. This bug did not affect public or private key mater…
- CVE-2023-0678MEDIUMCVSS 5.3EG 5.82023-02-04
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
- CVE-2023-0734MEDIUMCVSS 5.3EG 5.32023-03-05
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.
- CVE-2023-0813HIGHCVSS 7.5EG 8.62023-09-15
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in…
- CVE-2023-0822HIGHCVSS 8.8EG 8.82023-02-17
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization, which could allow an unauthorized user to bypass authorization and access privileged functionality.
- CVE-2023-0837MEDIUMCVSS 6.6EG 6.62023-06-14
An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings even though the options were locked. T…
- CVE-2023-0914MEDIUMCVSS 5.3EG 5.32023-02-19
Improper Authorization in GitHub repository pixelfed/pixelfed prior to 0.11.4.
- CVE-2023-1164HIGHCVSS 8.4EG 8.42023-03-03
A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. Affected by this issue is some unknown functionality of the component File Import. The manipulation leads to improper authorization. The attack …
- CVE-2023-1167MEDIUMCVSS 5.3EG 5.32023-04-05
Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 allows an unauthorized access to security reports in MR.
- CVE-2023-1256CRITICALCVSS 9.8EG 9.82023-03-16
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states.
- CVE-2023-1910MEDIUMCVSS 4.3EG 4.32023-06-09
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the get_remote_templates function in versions up to, and including, 1.8.3. This makes it pos…
- CVE-2023-20088HIGHCVSS 5.3EG 7.52023-03-03
A vulnerability in the nginx configurations that are provided as part of the VPN-less reverse proxy for Cisco Finesse could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for new and existing users …
- CVE-2023-20182MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted conta…
- CVE-2023-20183MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted conta…
- CVE-2023-20184MEDIUMCVSS 5.4EG 5.42023-05-18
Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted conta…
- CVE-2023-20186HIGHCVSS 8.0EG 8.02023-09-27
A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the …
- CVE-2023-21422MEDIUMCVSS 5.7EG 5.72023-02-09
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
- CVE-2023-21423MEDIUMCVSS 5.1EG 5.52023-02-09
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.
- CVE-2023-21424MEDIUMCVSS 5.1EG 5.12023-02-09
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.
- CVE-2023-21429MEDIUMCVSS 4.0EG 4.02023-02-09
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
Map vulnerabilities like CWE-285 to your infrastructure
EchelonGraph correlates every CVE — across CWE-285 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →