CWE-285 · 1,337 records
Improper Authorization
CVEs in this class
1,338 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
92Now | CVE-2021-28799Weaponized | Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)qnap · hybrid backup sync · CWE-285 | Critical9.8 | KEV | 78.3% | May 12, 2021 |
66This week | CVE-2025-29927Weaponized | Authorization Bypass in Next.js Middlewarevercel · next.js · CWE-285 | Critical9.1 | — | 99.2% | Mar 21, 2025 |
65This week | CVE-2026-58704Weaponized | In Cellular Modem, there is a possible permission bypass due to a logic error in the code.google · android · CWE-285 | High8.8 | KEV | 0.6% | Sep 15, 2026 |
59Plan | CVE-2023-32707Weaponized | ‘edit_user’ Capability Privilege Escalationsplunk · splunk · CWE-285 | High8.8 | — | 79.0% | Jun 1, 2023 |
59Plan | CVE-2023-22480Proof of concept | KubeOperator is vulnerable to unauthorized access to system APIfit2cloud · kubeoperator · CWE-285 | Critical9.8 | — | 66.8% | Jan 13, 2023 |
59Plan | CVE-2022-3229Weaponized | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenunifiedremote · unified remote · CWE-285 | Critical9.8 | — | 66.4% | Feb 6, 2023 |
52Plan | CVE-2023-48241Proof of concept | XWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest servicexwiki · xwiki · CWE-285 | High7.5 | — | 72.8% | Nov 20, 2023 |
49Plan | CVE-2023-2227Proof of concept | Improper Authorization in modoboa/modoboamodoboa · modoboa · CWE-285 | Critical9.1 | — | 44.0% | Apr 21, 2023 |
46Plan | CVE-2016-5676Weaponized | cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.netgear · readynas surveillance · CWE-285 | High7.5 | — | 53.7% | Aug 31, 2016 |
42Plan | CVE-2025-21400No exploit | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-285 | High8.0 | — | 34.5% | Feb 11, 2025 |
42Plan | CVE-2025-61928No exploit | Better Auth: Unauthenticated API key creation through api-key pluginbetter-auth · better-auth · CWE-285 | Critical9.3 | — | 17.9% | Oct 9, 2025 |
41Plan | CVE-2016-3352No exploit | Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makmicrosoft · windows 10 · CWE-285 | High8.8 | — | 20.8% | Sep 14, 2016 |
41Plan | CVE-2019-1912Proof of concept | Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerabilitycisco · sf-220-24 firmware · CWE-285 | Critical9.1 | — | 17.0% | Aug 7, 2019 |
41Plan | CVE-2022-0993No exploit | SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypasssiteground · siteground security · CWE-285 | Critical9.8 | — | 7.5% | Apr 19, 2022 |
41Plan | CVE-2021-42338No exploit | 4MOSAn GCB Doctor - Improper Authorization4mosan · gcb doctor · CWE-285 | Critical9.8 | — | 5.8% | Nov 19, 2021 |
41Plan | CVE-2019-7489Proof of concept | A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution.sonicwall · email security appliance · CWE-285 | Critical9.8 | — | 5.3% | Dec 23, 2019 |
41Plan | CVE-2021-37705No exploit | Improper Authorization and Origin Validation Error in OneFuzzmicrosoft · onefuzz · CWE-285 | Critical10.0 | — | 2.4% | Aug 13, 2021 |
40Plan | CVE-2023-50780Proof of concept | Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeansapache · artemis · CWE-285 | High8.8 | — | 17.5% | Oct 14, 2024 |
40Plan | CVE-2020-1745No exploit | A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.redhat · undertow · CWE-285 | Critical9.8 | — | 5.0% | Apr 28, 2020 |
40Plan | CVE-2017-6044No exploit | An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all sierra wireless · airlink raven xe firmware · CWE-285 | Critical9.8 | — | 4.3% | Jun 29, 2017 |
40Plan | CVE-2026-22252No exploit | LibreChat MCP Stdio Remote Command Executionlibrechat · librechat · CWE-285 | Critical9.9 | — | 4.1% | Jan 12, 2026 |
40Plan | CVE-2016-5799No exploit | Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attemptmoxa · oncell g3001 firmware · CWE-285 | Critical9.8 | — | 4.0% | Aug 23, 2016 |
40Plan | CVE-2024-34257Proof of concept | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrartotolink · ex1800t firmware · CWE-285 | Critical9.8 | — | 3.8% | May 8, 2024 |
40Plan | CVE-2022-21196No exploit | Airspan Networks Mimosa Improper Authorizationairspan · mimosa management platform · CWE-285 | Critical9.8 | — | 3.7% | Feb 18, 2022 |
40Plan | CVE-2017-16743No exploit | An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1phoenixcontact · fl switch 3005 firmware · CWE-285 | Critical9.8 | — | 3.1% | Jan 12, 2018 |
- CVE-2021-2879992Now
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
CriticalCVSS 9.8KEVWeaponizedEPSS 78%qnap · hybrid backup syncMay 12, 2021
- CVE-2025-2992766This week
Authorization Bypass in Next.js Middleware
CriticalCVSS 9.1WeaponizedEPSS 99%vercel · next.jsMar 21, 2025
- CVE-2026-5870465This week
In Cellular Modem, there is a possible permission bypass due to a logic error in the code.
HighCVSS 8.8KEVWeaponizedEPSS 1%google · androidSep 15, 2026
- CVE-2023-3270759Plan
‘edit_user’ Capability Privilege Escalation
HighCVSS 8.8WeaponizedEPSS 79%splunk · splunkJun 1, 2023
- CVE-2023-2248059Plan
KubeOperator is vulnerable to unauthorized access to system API
CriticalCVSS 9.8Proof of conceptEPSS 67%fit2cloud · kubeoperatorJan 13, 2023
- CVE-2022-322959Plan
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthen
CriticalCVSS 9.8WeaponizedEPSS 66%unifiedremote · unified remoteFeb 6, 2023
- CVE-2023-4824152Plan
XWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest service
HighCVSS 7.5Proof of conceptEPSS 73%xwiki · xwikiNov 20, 2023
- CVE-2023-222749Plan
Improper Authorization in modoboa/modoboa
CriticalCVSS 9.1Proof of conceptEPSS 44%modoboa · modoboaApr 21, 2023
- CVE-2016-567646Plan
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.
HighCVSS 7.5WeaponizedEPSS 54%netgear · readynas surveillanceAug 31, 2016
- CVE-2025-2140042Plan
Microsoft SharePoint Server Remote Code Execution Vulnerability
HighCVSS 8.0No exploitEPSS 34%microsoft · sharepoint serverFeb 11, 2025
- CVE-2025-6192842Plan
Better Auth: Unauthenticated API key creation through api-key plugin
CriticalCVSS 9.3No exploitEPSS 18%better-auth · better-authOct 9, 2025
- CVE-2016-335241Plan
Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which mak
HighCVSS 8.8No exploitEPSS 21%microsoft · windows 10Sep 14, 2016
- CVE-2019-191241Plan
Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerability
CriticalCVSS 9.1Proof of conceptEPSS 17%cisco · sf-220-24 firmwareAug 7, 2019
- CVE-2022-099341Plan
SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypass
CriticalCVSS 9.8No exploitEPSS 8%siteground · siteground securityApr 19, 2022
- CVE-2021-4233841Plan
4MOSAn GCB Doctor - Improper Authorization
CriticalCVSS 9.8No exploitEPSS 6%4mosan · gcb doctorNov 19, 2021
- CVE-2019-748941Plan
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution.
CriticalCVSS 9.8Proof of conceptEPSS 5%sonicwall · email security applianceDec 23, 2019
- CVE-2021-3770541Plan
Improper Authorization and Origin Validation Error in OneFuzz
CriticalCVSS 10.0No exploitEPSS 2%microsoft · onefuzzAug 13, 2021
- CVE-2023-5078040Plan
Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
HighCVSS 8.8Proof of conceptEPSS 17%apache · artemisOct 14, 2024
- CVE-2020-174540Plan
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.
CriticalCVSS 9.8No exploitEPSS 5%redhat · undertowApr 28, 2020
- CVE-2017-604440Plan
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all
CriticalCVSS 9.8No exploitEPSS 4%sierra wireless · airlink raven xe firmwareJun 29, 2017
- CVE-2026-2225240Plan
LibreChat MCP Stdio Remote Command Execution
CriticalCVSS 9.9No exploitEPSS 4%librechat · librechatJan 12, 2026
- CVE-2016-579940Plan
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempt
CriticalCVSS 9.8No exploitEPSS 4%moxa · oncell g3001 firmwareAug 23, 2016
- CVE-2024-3425740Plan
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrar
CriticalCVSS 9.8Proof of conceptEPSS 4%totolink · ex1800t firmwareMay 8, 2024
- CVE-2022-2119640Plan
Airspan Networks Mimosa Improper Authorization
CriticalCVSS 9.8No exploitEPSS 4%airspan · mimosa management platformFeb 18, 2022
- CVE-2017-1674340Plan
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1
CriticalCVSS 9.8No exploitEPSS 3%phoenixcontact · fl switch 3005 firmwareJan 12, 2018