CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,126 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 58 of 83
- CVE-2025-15406MEDIUMCVSS 8.8EG 6.32026-01-01
A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and m…
- CVE-2025-1542CRITICALCVSS 9.3EG 9.32025-03-26
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects …
- CVE-2025-15513MEDIUMCVSS 5.3EG 5.32026-01-14
The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatResponse() function in all versions up to, and including, 1.1.9. This makes it possible for …
- CVE-2025-15525MEDIUMCVSS 5.3EG 5.32026-01-31
The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to unauthorized access of data due to incorrect authorization on the parse_custom_args() function in all versions up to, and including, 7.8.1…
- CVE-2025-15633MEDIUMCVSS 6.5EG 6.52026-05-09
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables) and bypass privilege requirements via …
- CVE-2025-1792LOWCVSS 3.1EG 3.12025-05-30
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of p…
- CVE-2025-2003HIGHCVSS 7.1EG 7.12025-03-05
Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.
- CVE-2025-20257MEDIUMCVSS 6.5EG 6.52025-05-21
A vulnerability in an API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to generate fraudulent findings that are use…
- CVE-2025-20300MEDIUMCVSS 4.3EG 4.32025-07-07
In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.112, and 9.2.2406.119, a low-privileged user that does not hold the "admin" or "power" Splunk roles, and has…
- CVE-2025-20332MEDIUMCVSS 4.3EG 4.32025-08-06
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation…
- CVE-2025-20381MEDIUMCVSS 5.4EG 5.42025-12-03
In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP) tool could bypass the SPL command allowlist controls in MCP by embedding SPL commands as sub-searches, leading to unau…
- CVE-2025-2045MEDIUMCVSS 4.3EG 4.32025-03-06
Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.
- CVE-2025-20674CRITICALCVSS 9.8EG 9.82025-06-02
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2025-20701HIGHCVSS 8.8EG 8.82025-08-04
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not neede…
- CVE-2025-20999MEDIUMCVSS 4.1EG 4.12025-07-08
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
- CVE-2025-21403MEDIUMCVSS 6.4EG 6.42025-01-14
On-Premises Data Gateway Information Disclosure Vulnerability
- CVE-2025-21450CRITICALCVSS 9.1EG 9.12025-07-08
Cryptographic issue occurs due to use of insecure connection method while downloading.
- CVE-2025-21479CRITICALCVSS 8.6EG 9.0⚠ KEV2025-06-03
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- CVE-2025-21480CRITICALCVSS 8.6EG 9.0⚠ KEV2025-06-03
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
- CVE-2025-21502MEDIUMCVSS 4.8EG 4.82025-01-21
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, …
- CVE-2025-21506HIGHCVSS 8.1EG 8.12025-01-21
Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker…
- CVE-2025-21516HIGHCVSS 8.1EG 8.12025-01-21
Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with netw…
- CVE-2025-21517MEDIUMCVSS 4.3EG 4.32025-01-21
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2025-21519MEDIUMCVSS 4.4EG 4.42025-01-21
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allow…
- CVE-2025-21532HIGHCVSS 7.8EG 7.82025-01-21
Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install). Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the inf…
- CVE-2025-21533MEDIUMCVSS 5.5EG 5.52025-01-21
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.24 and prior to 7.1.6. Easily exploitable vulnerability allows low privileged attacker wi…
- CVE-2025-21537MEDIUMCVSS 5.4EG 5.42025-01-21
Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2025-21539MEDIUMCVSS 5.4EG 5.42025-01-21
Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with netwo…
- CVE-2025-21540MEDIUMCVSS 5.4EG 5.42025-01-21
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows …
- CVE-2025-21546LOWCVSS 3.8EG 3.82025-01-21
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows …
- CVE-2025-21553MEDIUMCVSS 4.2EG 4.22025-01-21
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Cre…
- CVE-2025-21554MEDIUMCVSS 5.3EG 5.32025-01-21
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerabilit…
- CVE-2025-21555MEDIUMCVSS 5.5EG 5.52025-01-21
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attack…
- CVE-2025-21556CRITICALCVSS 9.9EG 9.92025-01-21
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with…
- CVE-2025-21557MEDIUMCVSS 5.4EG 5.42025-01-21
Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle A…
- CVE-2025-21558MEDIUMCVSS 5.4EG 5.42025-01-21
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0 and 22.…
- CVE-2025-21560MEDIUMCVSS 6.5EG 6.52025-01-21
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker wi…
- CVE-2025-21561MEDIUMCVSS 5.4EG 5.42025-01-21
Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network a…
- CVE-2025-21562MEDIUMCVSS 4.3EG 4.32025-01-21
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privile…
- CVE-2025-21563MEDIUMCVSS 4.3EG 4.32025-01-21
Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privile…
- CVE-2025-21565HIGHCVSS 7.5EG 7.52025-01-21
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access vi…
- CVE-2025-21567MEDIUMCVSS 4.3EG 4.32025-01-21
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network ac…
- CVE-2025-21568MEDIUMCVSS 4.5EG 4.52025-01-21
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security). The supported version that is affected is 11.2.19.0.000. Easily exploitable vulnerability allows high privileg…
- CVE-2025-21569MEDIUMCVSS 6.6EG 6.62025-01-21
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). The supported version that is affected is 11.2.19.0.000. Difficult to exploit vulnerability allows high privileged at…
- CVE-2025-21570MEDIUMCVSS 6.1EG 6.12025-01-21
Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login). The supported version that is affected is 8.2.3. Easily exploitable vulnerability allows unauthenticated attacker w…
- CVE-2025-21582MEDIUMCVSS 6.1EG 6.12025-04-15
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker wi…
- CVE-2025-2201MEDIUMCVSS 6.9EG 6.92025-03-17
Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and m…
- CVE-2025-2202MEDIUMCVSS 6.9EG 6.92025-03-17
Broken access control vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability allows an attacker to obtain sensitive information about other users such as id, name, login and email.
- CVE-2025-2242HIGHCVSS 7.5EG 7.52025-03-27
An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a r…
- CVE-2025-22428HIGHCVSS 7.8EG 7.82025-09-02
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on the secondary user from the primary user due to a logic error in the code. This could lead to local escalation of privil…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →