CWE-863 · 3 387 записей
Incorrect Authorization
CVE этого класса
3 411 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2023-22518Готовый эксплойт | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Критическая9,8 | KEV | 100,0 % | 31 окт. 2023 г. |
99Срочно | CVE-2023-38035Готовый эксплойт | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass aivanti · mobileiron sentry · CWE-863 | Критическая9,8 | KEV | 100,0 % | 21 авг. 2023 г. |
99Срочно | CVE-2024-38856Готовый эксплойт | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering codeapache · ofbiz · CWE-863 | Критическая9,8 | KEV | 99,4 % | 5 авг. 2024 г. |
96Срочно | CVE-2025-54253Готовый эксплойт | Adobe Experience Manager | Incorrect Authorization (CWE-863)adobe · experience manager forms · CWE-863 | Критическая10,0 | KEV | 88,0 % | 5 авг. 2025 г. |
95Срочно | CVE-2019-7192Готовый эксплойт | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.qnap · photo station · CWE-863 | Критическая9,8 | KEV | 88,1 % | 5 дек. 2019 г. |
92Срочно | CVE-2026-71362Готовый эксплойт | Adobe Commerce | Incorrect Authorization (CWE-863)adobe · commerce · CWE-863 | Критическая9,1 | KEV | 87,5 % | 11 авг. 2026 г. |
86Срочно | CVE-2021-40655Готовый эксплойт | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.dlink · dir-605l firmware · CWE-863 | Высокая7,5 | KEV | 86,7 % | 24 сент. 2021 г. |
85Срочно | CVE-2018-13382Готовый эксплойт | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 tfortinet · fortiproxy · CWE-863 | Высокая7,5 | KEV | 81,7 % | 4 июн. 2019 г. |
70На этой неделе | CVE-2023-24880Готовый эксплойт | Windows SmartScreen Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-863 | Средняя4,4 | KEV | 78,0 % | 14 мар. 2023 г. |
68На этой неделе | CVE-2021-3560Готовый эксплойт | It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestorpolkit project · polkit · CWE-863 | Высокая7,8 | KEV | 23,7 % | 16 февр. 2022 г. |
68На этой неделе | CVE-2026-42016Готовый эксплойт | Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalationjfrog · artifactory · CWE-863 | Высокая8,8 | KEV | 8,6 % | 27 июл. 2026 г. |
64На этой неделе | CVE-2024-6782Готовый эксплойт | Calibre Remote Code Executioncalibre · calibre · CWE-863 | Критическая9,8 | — | 84,1 % | 6 авг. 2024 г. |
64На этой неделе | CVE-2025-21479Готовый эксплойт | Incorrect Authorization in Graphicsqualcomm · aqt1000 firmware · CWE-863 | Высокая8,6 | KEV | 0,8 % | 3 июн. 2025 г. |
64На этой неделе | CVE-2025-21480Готовый эксплойт | Incorrect Authorization in Graphics Windowsqualcomm · aqt1000 firmware · CWE-863 | Высокая8,6 | KEV | 0,5 % | 3 июн. 2025 г. |
63На этой неделе | CVE-2020-13957Proof of concept | Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for apache · solr · CWE-863 | Критическая9,8 | — | 79,3 % | 13 окт. 2020 г. |
63На этой неделе | CVE-2023-21715Готовый эксплойт | Microsoft Publisher Security Feature Bypass Vulnerabilitymicrosoft · 365 apps · CWE-863 | Высокая7,3 | KEV | 12,0 % | 14 февр. 2023 г. |
61На этой неделе | CVE-2021-30533Готовый эксплойт | Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrigoogle · chrome · CWE-863 | Средняя6,5 | KEV | 16,6 % | 7 июн. 2021 г. |
61На этой неделе | CVE-2024-21287Готовый эксплойт | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension).oracle · agile product lifecycle management · CWE-863 | Высокая7,5 | KEV | 1,7 % | 18 нояб. 2024 г. |
57В плане | CVE-2019-7304Proof of concept | Local privilege escalation via snapd socketcanonical · snapd · CWE-863 | Критическая9,8 | — | 60,8 % | 23 апр. 2019 г. |
56В плане | CVE-2021-45466Эксплойта нет | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to acontrol-webpanel · webpanel · CWE-863 | Критическая9,8 | — | 55,3 % | 26 дек. 2022 г. |
55В плане | CVE-2025-24200Готовый эксплойт | An authorization issue was addressed with improved state management.apple · ipados · CWE-863 | Средняя6,1 | KEV | 4,5 % | 10 февр. 2025 г. |
54В плане | CVE-2023-35166Эксплойта нет | Privilege escalation (PR) from account through TipsPanelxwiki · xwiki · CWE-863 | Высокая8,8 | — | 62,2 % | 20 июн. 2023 г. |
53В плане | CVE-2010-2965Эксплойта нет | The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with frockwellautomation · 1756-enbt\/a firmware · CWE-863 | Критическая9,8 | — | 47,4 % | 5 авг. 2010 г. |
52В плане | CVE-2023-34051Proof of concept | VMware Aria Operations for Logs contains an authentication bypass vulnerability.vmware · aria operations for logs · CWE-863 | Критическая9,8 | — | 44,7 % | 20 окт. 2023 г. |
52В плане | CVE-2025-55177Готовый эксплойт | Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25whatsapp · whatsapp · CWE-863 | Средняя5,4 | KEV | 4,3 % | 29 авг. 2025 г. |
- CVE-2023-2251899Срочно
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center31 окт. 2023 г.
- CVE-2023-3803599Срочно
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · mobileiron sentry21 авг. 2023 г.
- CVE-2024-3885699Срочно
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %apache · ofbiz5 авг. 2024 г.
- CVE-2025-5425396Срочно
Adobe Experience Manager | Incorrect Authorization (CWE-863)
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 88 %adobe · experience manager forms5 авг. 2025 г.
- CVE-2019-719295Срочно
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 88 %qnap · photo station5 дек. 2019 г.
- CVE-2026-7136292Срочно
Adobe Commerce | Incorrect Authorization (CWE-863)
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 88 %adobe · commerce11 авг. 2026 г.
- CVE-2021-4065586Срочно
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 87 %dlink · dir-605l firmware24 сент. 2021 г.
- CVE-2018-1338285Срочно
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 t
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 82 %fortinet · fortiproxy4 июн. 2019 г.
- CVE-2023-2488070На этой неделе
Windows SmartScreen Security Feature Bypass Vulnerability
СредняяCVSS 4,4KEVГотовый эксплойтEPSS 78 %microsoft · windows 10 160714 мар. 2023 г.
- CVE-2021-356068На этой неделе
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 24 %polkit project · polkit16 февр. 2022 г.
- CVE-2026-4201668На этой неделе
Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 9 %jfrog · artifactory27 июл. 2026 г.
- CVE-2024-678264На этой неделе
Calibre Remote Code Execution
КритическаяCVSS 9,8Готовый эксплойтEPSS 84 %calibre · calibre6 авг. 2024 г.
- CVE-2025-2147964На этой неделе
Incorrect Authorization in Graphics
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 1 %qualcomm · aqt1000 firmware3 июн. 2025 г.
- CVE-2025-2148064На этой неделе
Incorrect Authorization in Graphics Windows
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 0 %qualcomm · aqt1000 firmware3 июн. 2025 г.
- CVE-2020-1395763На этой неделе
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for
КритическаяCVSS 9,8Proof of conceptEPSS 79 %apache · solr13 окт. 2020 г.
- CVE-2023-2171563На этой неделе
Microsoft Publisher Security Feature Bypass Vulnerability
ВысокаяCVSS 7,3KEVГотовый эксплойтEPSS 12 %microsoft · 365 apps14 февр. 2023 г.
- CVE-2021-3053361На этой неделе
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restri
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 17 %google · chrome7 июн. 2021 г.
- CVE-2024-2128761На этой неделе
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension).
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 2 %oracle · agile product lifecycle management18 нояб. 2024 г.
- CVE-2019-730457В плане
Local privilege escalation via snapd socket
КритическаяCVSS 9,8Proof of conceptEPSS 61 %canonical · snapd23 апр. 2019 г.
- CVE-2021-4546656В плане
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to a
КритическаяCVSS 9,8Эксплойта нетEPSS 55 %control-webpanel · webpanel26 дек. 2022 г.
- CVE-2025-2420055В плане
An authorization issue was addressed with improved state management.
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 4 %apple · ipados10 февр. 2025 г.
- CVE-2023-3516654В плане
Privilege escalation (PR) from account through TipsPanel
ВысокаяCVSS 8,8Эксплойта нетEPSS 62 %xwiki · xwiki20 июн. 2023 г.
- CVE-2010-296553В плане
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with f
КритическаяCVSS 9,8Эксплойта нетEPSS 47 %rockwellautomation · 1756-enbt\/a firmware5 авг. 2010 г.
- CVE-2023-3405152В плане
VMware Aria Operations for Logs contains an authentication bypass vulnerability.
КритическаяCVSS 9,8Proof of conceptEPSS 45 %vmware · aria operations for logs20 окт. 2023 г.
- CVE-2025-5517752В плане
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25
СредняяCVSS 5,4KEVГотовый эксплойтEPSS 4 %whatsapp · whatsapp29 авг. 2025 г.