CWE-285 · 1 337 записей
Improper Authorization
CVE этого класса
1 338 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
92Срочно | CVE-2021-28799Готовый эксплойт | Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)qnap · hybrid backup sync · CWE-285 | Критическая9,8 | KEV | 78,3 % | 12 мая 2021 г. |
66На этой неделе | CVE-2025-29927Готовый эксплойт | Authorization Bypass in Next.js Middlewarevercel · next.js · CWE-285 | Критическая9,1 | — | 99,2 % | 21 мар. 2025 г. |
65На этой неделе | CVE-2026-58704Готовый эксплойт | In Cellular Modem, there is a possible permission bypass due to a logic error in the code.google · android · CWE-285 | Высокая8,8 | KEV | 0,6 % | 15 сент. 2026 г. |
59В плане | CVE-2023-32707Готовый эксплойт | ‘edit_user’ Capability Privilege Escalationsplunk · splunk · CWE-285 | Высокая8,8 | — | 79,0 % | 1 июн. 2023 г. |
59В плане | CVE-2023-22480Proof of concept | KubeOperator is vulnerable to unauthorized access to system APIfit2cloud · kubeoperator · CWE-285 | Критическая9,8 | — | 66,8 % | 13 янв. 2023 г. |
59В плане | CVE-2022-3229Готовый эксплойт | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenunifiedremote · unified remote · CWE-285 | Критическая9,8 | — | 66,4 % | 6 февр. 2023 г. |
52В плане | CVE-2023-48241Proof of concept | XWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest servicexwiki · xwiki · CWE-285 | Высокая7,5 | — | 72,8 % | 20 нояб. 2023 г. |
49В плане | CVE-2023-2227Proof of concept | Improper Authorization in modoboa/modoboamodoboa · modoboa · CWE-285 | Критическая9,1 | — | 44,0 % | 21 апр. 2023 г. |
46В плане | CVE-2016-5676Готовый эксплойт | cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.netgear · readynas surveillance · CWE-285 | Высокая7,5 | — | 53,7 % | 31 авг. 2016 г. |
42В плане | CVE-2025-21400Эксплойта нет | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-285 | Высокая8,0 | — | 34,5 % | 11 февр. 2025 г. |
42В плане | CVE-2025-61928Эксплойта нет | Better Auth: Unauthenticated API key creation through api-key pluginbetter-auth · better-auth · CWE-285 | Критическая9,3 | — | 17,9 % | 9 окт. 2025 г. |
41В плане | CVE-2016-3352Эксплойта нет | Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makmicrosoft · windows 10 · CWE-285 | Высокая8,8 | — | 20,8 % | 14 сент. 2016 г. |
41В плане | CVE-2019-1912Proof of concept | Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerabilitycisco · sf-220-24 firmware · CWE-285 | Критическая9,1 | — | 17,0 % | 7 авг. 2019 г. |
41В плане | CVE-2022-0993Эксплойта нет | SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypasssiteground · siteground security · CWE-285 | Критическая9,8 | — | 7,5 % | 19 апр. 2022 г. |
41В плане | CVE-2021-42338Эксплойта нет | 4MOSAn GCB Doctor - Improper Authorization4mosan · gcb doctor · CWE-285 | Критическая9,8 | — | 5,8 % | 19 нояб. 2021 г. |
41В плане | CVE-2019-7489Proof of concept | A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution.sonicwall · email security appliance · CWE-285 | Критическая9,8 | — | 5,3 % | 23 дек. 2019 г. |
41В плане | CVE-2021-37705Эксплойта нет | Improper Authorization and Origin Validation Error in OneFuzzmicrosoft · onefuzz · CWE-285 | Критическая10,0 | — | 2,4 % | 13 авг. 2021 г. |
40В плане | CVE-2023-50780Proof of concept | Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeansapache · artemis · CWE-285 | Высокая8,8 | — | 17,5 % | 14 окт. 2024 г. |
40В плане | CVE-2020-1745Эксплойта нет | A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.redhat · undertow · CWE-285 | Критическая9,8 | — | 5,0 % | 28 апр. 2020 г. |
40В плане | CVE-2017-6044Эксплойта нет | An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all sierra wireless · airlink raven xe firmware · CWE-285 | Критическая9,8 | — | 4,3 % | 29 июн. 2017 г. |
40В плане | CVE-2026-22252Эксплойта нет | LibreChat MCP Stdio Remote Command Executionlibrechat · librechat · CWE-285 | Критическая9,9 | — | 4,1 % | 12 янв. 2026 г. |
40В плане | CVE-2016-5799Эксплойта нет | Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attemptmoxa · oncell g3001 firmware · CWE-285 | Критическая9,8 | — | 4,0 % | 23 авг. 2016 г. |
40В плане | CVE-2024-34257Proof of concept | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrartotolink · ex1800t firmware · CWE-285 | Критическая9,8 | — | 3,8 % | 8 мая 2024 г. |
40В плане | CVE-2022-21196Эксплойта нет | Airspan Networks Mimosa Improper Authorizationairspan · mimosa management platform · CWE-285 | Критическая9,8 | — | 3,7 % | 18 февр. 2022 г. |
40В плане | CVE-2017-16743Эксплойта нет | An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1phoenixcontact · fl switch 3005 firmware · CWE-285 | Критическая9,8 | — | 3,1 % | 12 янв. 2018 г. |
- CVE-2021-2879992Срочно
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 78 %qnap · hybrid backup sync12 мая 2021 г.
- CVE-2025-2992766На этой неделе
Authorization Bypass in Next.js Middleware
КритическаяCVSS 9,1Готовый эксплойтEPSS 99 %vercel · next.js21 мар. 2025 г.
- CVE-2026-5870465На этой неделе
In Cellular Modem, there is a possible permission bypass due to a logic error in the code.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 1 %google · android15 сент. 2026 г.
- CVE-2023-3270759В плане
‘edit_user’ Capability Privilege Escalation
ВысокаяCVSS 8,8Готовый эксплойтEPSS 79 %splunk · splunk1 июн. 2023 г.
- CVE-2023-2248059В плане
KubeOperator is vulnerable to unauthorized access to system API
КритическаяCVSS 9,8Proof of conceptEPSS 67 %fit2cloud · kubeoperator13 янв. 2023 г.
- CVE-2022-322959В плане
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthen
КритическаяCVSS 9,8Готовый эксплойтEPSS 66 %unifiedremote · unified remote6 февр. 2023 г.
- CVE-2023-4824152В плане
XWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest service
ВысокаяCVSS 7,5Proof of conceptEPSS 73 %xwiki · xwiki20 нояб. 2023 г.
- CVE-2023-222749В плане
Improper Authorization in modoboa/modoboa
КритическаяCVSS 9,1Proof of conceptEPSS 44 %modoboa · modoboa21 апр. 2023 г.
- CVE-2016-567646В плане
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 54 %netgear · readynas surveillance31 авг. 2016 г.
- CVE-2025-2140042В плане
Microsoft SharePoint Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,0Эксплойта нетEPSS 34 %microsoft · sharepoint server11 февр. 2025 г.
- CVE-2025-6192842В плане
Better Auth: Unauthenticated API key creation through api-key plugin
КритическаяCVSS 9,3Эксплойта нетEPSS 18 %better-auth · better-auth9 окт. 2025 г.
- CVE-2016-335241В плане
Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which mak
ВысокаяCVSS 8,8Эксплойта нетEPSS 21 %microsoft · windows 1014 сент. 2016 г.
- CVE-2019-191241В плане
Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerability
КритическаяCVSS 9,1Proof of conceptEPSS 17 %cisco · sf-220-24 firmware7 авг. 2019 г.
- CVE-2022-099341В плане
SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %siteground · siteground security19 апр. 2022 г.
- CVE-2021-4233841В плане
4MOSAn GCB Doctor - Improper Authorization
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %4mosan · gcb doctor19 нояб. 2021 г.
- CVE-2019-748941В плане
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %sonicwall · email security appliance23 дек. 2019 г.
- CVE-2021-3770541В плане
Improper Authorization and Origin Validation Error in OneFuzz
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %microsoft · onefuzz13 авг. 2021 г.
- CVE-2023-5078040В плане
Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
ВысокаяCVSS 8,8Proof of conceptEPSS 17 %apache · artemis14 окт. 2024 г.
- CVE-2020-174540В плане
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %redhat · undertow28 апр. 2020 г.
- CVE-2017-604440В плане
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %sierra wireless · airlink raven xe firmware29 июн. 2017 г.
- CVE-2026-2225240В плане
LibreChat MCP Stdio Remote Command Execution
КритическаяCVSS 9,9Эксплойта нетEPSS 4 %librechat · librechat12 янв. 2026 г.
- CVE-2016-579940В плане
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempt
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %moxa · oncell g3001 firmware23 авг. 2016 г.
- CVE-2024-3425740В плане
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrar
КритическаяCVSS 9,8Proof of conceptEPSS 4 %totolink · ex1800t firmware8 мая 2024 г.
- CVE-2022-2119640В плане
Airspan Networks Mimosa Improper Authorization
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %airspan · mimosa management platform18 февр. 2022 г.
- CVE-2017-1674340В плане
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %phoenixcontact · fl switch 3005 firmware12 янв. 2018 г.