CWE-863 · 3,387 records
Incorrect Authorization
CVEs in this class
3,411 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2023-22518Weaponized | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Critical9.8 | KEV | 100.0% | Oct 31, 2023 |
99Now | CVE-2023-38035Weaponized | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass aivanti · mobileiron sentry · CWE-863 | Critical9.8 | KEV | 100.0% | Aug 21, 2023 |
99Now | CVE-2024-38856Weaponized | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering codeapache · ofbiz · CWE-863 | Critical9.8 | KEV | 99.4% | Aug 5, 2024 |
96Now | CVE-2025-54253Weaponized | Adobe Experience Manager | Incorrect Authorization (CWE-863)adobe · experience manager forms · CWE-863 | Critical10.0 | KEV | 88.0% | Aug 5, 2025 |
95Now | CVE-2019-7192Weaponized | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.qnap · photo station · CWE-863 | Critical9.8 | KEV | 88.1% | Dec 5, 2019 |
92Now | CVE-2026-71362Weaponized | Adobe Commerce | Incorrect Authorization (CWE-863)adobe · commerce · CWE-863 | Critical9.1 | KEV | 87.5% | Aug 11, 2026 |
86Now | CVE-2021-40655Weaponized | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.dlink · dir-605l firmware · CWE-863 | High7.5 | KEV | 86.7% | Sep 24, 2021 |
85Now | CVE-2018-13382Weaponized | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 tfortinet · fortiproxy · CWE-863 | High7.5 | KEV | 81.7% | Jun 4, 2019 |
70This week | CVE-2023-24880Weaponized | Windows SmartScreen Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-863 | Medium4.4 | KEV | 78.0% | Mar 14, 2023 |
68This week | CVE-2021-3560Weaponized | It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestorpolkit project · polkit · CWE-863 | High7.8 | KEV | 23.7% | Feb 16, 2022 |
68This week | CVE-2026-42016Weaponized | Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalationjfrog · artifactory · CWE-863 | High8.8 | KEV | 8.6% | Jul 27, 2026 |
64This week | CVE-2024-6782Weaponized | Calibre Remote Code Executioncalibre · calibre · CWE-863 | Critical9.8 | — | 84.1% | Aug 6, 2024 |
64This week | CVE-2025-21479Weaponized | Incorrect Authorization in Graphicsqualcomm · aqt1000 firmware · CWE-863 | High8.6 | KEV | 0.8% | Jun 3, 2025 |
64This week | CVE-2025-21480Weaponized | Incorrect Authorization in Graphics Windowsqualcomm · aqt1000 firmware · CWE-863 | High8.6 | KEV | 0.5% | Jun 3, 2025 |
63This week | CVE-2020-13957Proof of concept | Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for apache · solr · CWE-863 | Critical9.8 | — | 79.3% | Oct 13, 2020 |
63This week | CVE-2023-21715Weaponized | Microsoft Publisher Security Feature Bypass Vulnerabilitymicrosoft · 365 apps · CWE-863 | High7.3 | KEV | 12.0% | Feb 14, 2023 |
61This week | CVE-2021-30533Weaponized | Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrigoogle · chrome · CWE-863 | Medium6.5 | KEV | 16.6% | Jun 7, 2021 |
61This week | CVE-2024-21287Weaponized | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension).oracle · agile product lifecycle management · CWE-863 | High7.5 | KEV | 1.7% | Nov 18, 2024 |
57Plan | CVE-2019-7304Proof of concept | Local privilege escalation via snapd socketcanonical · snapd · CWE-863 | Critical9.8 | — | 60.8% | Apr 23, 2019 |
56Plan | CVE-2021-45466No exploit | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to acontrol-webpanel · webpanel · CWE-863 | Critical9.8 | — | 55.3% | Dec 26, 2022 |
55Plan | CVE-2025-24200Weaponized | An authorization issue was addressed with improved state management.apple · ipados · CWE-863 | Medium6.1 | KEV | 4.5% | Feb 10, 2025 |
54Plan | CVE-2023-35166No exploit | Privilege escalation (PR) from account through TipsPanelxwiki · xwiki · CWE-863 | High8.8 | — | 62.2% | Jun 20, 2023 |
53Plan | CVE-2010-2965No exploit | The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with frockwellautomation · 1756-enbt\/a firmware · CWE-863 | Critical9.8 | — | 47.4% | Aug 5, 2010 |
52Plan | CVE-2023-34051Proof of concept | VMware Aria Operations for Logs contains an authentication bypass vulnerability.vmware · aria operations for logs · CWE-863 | Critical9.8 | — | 44.7% | Oct 20, 2023 |
52Plan | CVE-2025-55177Weaponized | Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25whatsapp · whatsapp · CWE-863 | Medium5.4 | KEV | 4.3% | Aug 29, 2025 |
- CVE-2023-2251899Now
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence data centerOct 31, 2023
- CVE-2023-3803599Now
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · mobileiron sentryAug 21, 2023
- CVE-2024-3885699Now
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
CriticalCVSS 9.8KEVWeaponizedEPSS 99%apache · ofbizAug 5, 2024
- CVE-2025-5425396Now
Adobe Experience Manager | Incorrect Authorization (CWE-863)
CriticalCVSS 10.0KEVWeaponizedEPSS 88%adobe · experience manager formsAug 5, 2025
- CVE-2019-719295Now
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.
CriticalCVSS 9.8KEVWeaponizedEPSS 88%qnap · photo stationDec 5, 2019
- CVE-2026-7136292Now
Adobe Commerce | Incorrect Authorization (CWE-863)
CriticalCVSS 9.1KEVWeaponizedEPSS 88%adobe · commerceAug 11, 2026
- CVE-2021-4065586Now
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.
HighCVSS 7.5KEVWeaponizedEPSS 87%dlink · dir-605l firmwareSep 24, 2021
- CVE-2018-1338285Now
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 t
HighCVSS 7.5KEVWeaponizedEPSS 82%fortinet · fortiproxyJun 4, 2019
- CVE-2023-2488070This week
Windows SmartScreen Security Feature Bypass Vulnerability
MediumCVSS 4.4KEVWeaponizedEPSS 78%microsoft · windows 10 1607Mar 14, 2023
- CVE-2021-356068This week
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor
HighCVSS 7.8KEVWeaponizedEPSS 24%polkit project · polkitFeb 16, 2022
- CVE-2026-4201668This week
Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
HighCVSS 8.8KEVWeaponizedEPSS 9%jfrog · artifactoryJul 27, 2026
- CVE-2024-678264This week
Calibre Remote Code Execution
CriticalCVSS 9.8WeaponizedEPSS 84%calibre · calibreAug 6, 2024
- CVE-2025-2147964This week
Incorrect Authorization in Graphics
HighCVSS 8.6KEVWeaponizedEPSS 1%qualcomm · aqt1000 firmwareJun 3, 2025
- CVE-2025-2148064This week
Incorrect Authorization in Graphics Windows
HighCVSS 8.6KEVWeaponizedEPSS 0%qualcomm · aqt1000 firmwareJun 3, 2025
- CVE-2020-1395763This week
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for
CriticalCVSS 9.8Proof of conceptEPSS 79%apache · solrOct 13, 2020
- CVE-2023-2171563This week
Microsoft Publisher Security Feature Bypass Vulnerability
HighCVSS 7.3KEVWeaponizedEPSS 12%microsoft · 365 appsFeb 14, 2023
- CVE-2021-3053361This week
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restri
MediumCVSS 6.5KEVWeaponizedEPSS 17%google · chromeJun 7, 2021
- CVE-2024-2128761This week
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension).
HighCVSS 7.5KEVWeaponizedEPSS 2%oracle · agile product lifecycle managementNov 18, 2024
- CVE-2019-730457Plan
Local privilege escalation via snapd socket
CriticalCVSS 9.8Proof of conceptEPSS 61%canonical · snapdApr 23, 2019
- CVE-2021-4546656Plan
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to a
CriticalCVSS 9.8No exploitEPSS 55%control-webpanel · webpanelDec 26, 2022
- CVE-2025-2420055Plan
An authorization issue was addressed with improved state management.
MediumCVSS 6.1KEVWeaponizedEPSS 4%apple · ipadosFeb 10, 2025
- CVE-2023-3516654Plan
Privilege escalation (PR) from account through TipsPanel
HighCVSS 8.8No exploitEPSS 62%xwiki · xwikiJun 20, 2023
- CVE-2010-296553Plan
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with f
CriticalCVSS 9.8No exploitEPSS 47%rockwellautomation · 1756-enbt\/a firmwareAug 5, 2010
- CVE-2023-3405152Plan
VMware Aria Operations for Logs contains an authentication bypass vulnerability.
CriticalCVSS 9.8Proof of conceptEPSS 45%vmware · aria operations for logsOct 20, 2023
- CVE-2025-5517752Plan
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25
MediumCVSS 5.4KEVWeaponizedEPSS 4%whatsapp · whatsappAug 29, 2025