CWE-285 · 1.337 kayıt
Improper Authorization
Bu sınıftaki CVE’ler
1.338 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
92Hemen | CVE-2021-28799Silahlaştırılmış | Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)qnap · hybrid backup sync · CWE-285 | Kritik9,8 | KEV | %78,3 | 12 May 2021 |
66Bu hafta | CVE-2025-29927Silahlaştırılmış | Authorization Bypass in Next.js Middlewarevercel · next.js · CWE-285 | Kritik9,1 | — | %99,2 | 21 Mar 2025 |
65Bu hafta | CVE-2026-58704Silahlaştırılmış | In Cellular Modem, there is a possible permission bypass due to a logic error in the code.google · android · CWE-285 | Yüksek8,8 | KEV | %0,6 | 15 Eyl 2026 |
59Planlayın | CVE-2023-32707Silahlaştırılmış | ‘edit_user’ Capability Privilege Escalationsplunk · splunk · CWE-285 | Yüksek8,8 | — | %79,0 | 1 Haz 2023 |
59Planlayın | CVE-2023-22480Kavram kanıtı | KubeOperator is vulnerable to unauthorized access to system APIfit2cloud · kubeoperator · CWE-285 | Kritik9,8 | — | %66,8 | 13 Oca 2023 |
59Planlayın | CVE-2022-3229Silahlaştırılmış | Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenunifiedremote · unified remote · CWE-285 | Kritik9,8 | — | %66,4 | 6 Şub 2023 |
52Planlayın | CVE-2023-48241Kavram kanıtı | XWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest servicexwiki · xwiki · CWE-285 | Yüksek7,5 | — | %72,8 | 20 Kas 2023 |
49Planlayın | CVE-2023-2227Kavram kanıtı | Improper Authorization in modoboa/modoboamodoboa · modoboa · CWE-285 | Kritik9,1 | — | %44,0 | 21 Nis 2023 |
46Planlayın | CVE-2016-5676Silahlaştırılmış | cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.netgear · readynas surveillance · CWE-285 | Yüksek7,5 | — | %53,7 | 31 Ağu 2016 |
42Planlayın | CVE-2025-21400İstismar yok | Microsoft SharePoint Server Remote Code Execution Vulnerabilitymicrosoft · sharepoint server · CWE-285 | Yüksek8,0 | — | %34,5 | 11 Şub 2025 |
42Planlayın | CVE-2025-61928İstismar yok | Better Auth: Unauthenticated API key creation through api-key pluginbetter-auth · better-auth · CWE-285 | Kritik9,3 | — | %17,9 | 9 Eki 2025 |
41Planlayın | CVE-2016-3352İstismar yok | Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makmicrosoft · windows 10 · CWE-285 | Yüksek8,8 | — | %20,8 | 14 Eyl 2016 |
41Planlayın | CVE-2019-1912Kavram kanıtı | Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerabilitycisco · sf-220-24 firmware · CWE-285 | Kritik9,1 | — | %17,0 | 7 Ağu 2019 |
41Planlayın | CVE-2022-0993İstismar yok | SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypasssiteground · siteground security · CWE-285 | Kritik9,8 | — | %7,5 | 19 Nis 2022 |
41Planlayın | CVE-2021-42338İstismar yok | 4MOSAn GCB Doctor - Improper Authorization4mosan · gcb doctor · CWE-285 | Kritik9,8 | — | %5,8 | 19 Kas 2021 |
41Planlayın | CVE-2019-7489Kavram kanıtı | A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution.sonicwall · email security appliance · CWE-285 | Kritik9,8 | — | %5,3 | 23 Ara 2019 |
41Planlayın | CVE-2021-37705İstismar yok | Improper Authorization and Origin Validation Error in OneFuzzmicrosoft · onefuzz · CWE-285 | Kritik10,0 | — | %2,4 | 13 Ağu 2021 |
40Planlayın | CVE-2023-50780Kavram kanıtı | Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeansapache · artemis · CWE-285 | Yüksek8,8 | — | %17,5 | 14 Eki 2024 |
40Planlayın | CVE-2020-1745İstismar yok | A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.redhat · undertow · CWE-285 | Kritik9,8 | — | %5,0 | 28 Nis 2020 |
40Planlayın | CVE-2017-6044İstismar yok | An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all sierra wireless · airlink raven xe firmware · CWE-285 | Kritik9,8 | — | %4,3 | 29 Haz 2017 |
40Planlayın | CVE-2026-22252İstismar yok | LibreChat MCP Stdio Remote Command Executionlibrechat · librechat · CWE-285 | Kritik9,9 | — | %4,1 | 12 Oca 2026 |
40Planlayın | CVE-2016-5799İstismar yok | Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attemptmoxa · oncell g3001 firmware · CWE-285 | Kritik9,8 | — | %4,0 | 23 Ağu 2016 |
40Planlayın | CVE-2024-34257Kavram kanıtı | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrartotolink · ex1800t firmware · CWE-285 | Kritik9,8 | — | %3,8 | 8 May 2024 |
40Planlayın | CVE-2022-21196İstismar yok | Airspan Networks Mimosa Improper Authorizationairspan · mimosa management platform · CWE-285 | Kritik9,8 | — | %3,7 | 18 Şub 2022 |
40Planlayın | CVE-2017-16743İstismar yok | An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1phoenixcontact · fl switch 3005 firmware · CWE-285 | Kritik9,8 | — | %3,1 | 12 Oca 2018 |
- CVE-2021-2879992Hemen
Improper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %78qnap · hybrid backup sync12 May 2021
- CVE-2025-2992766Bu hafta
Authorization Bypass in Next.js Middleware
KritikCVSS 9,1SilahlaştırılmışEPSS %99vercel · next.js21 Mar 2025
- CVE-2026-5870465Bu hafta
In Cellular Modem, there is a possible permission bypass due to a logic error in the code.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %1google · android15 Eyl 2026
- CVE-2023-3270759Planlayın
‘edit_user’ Capability Privilege Escalation
YüksekCVSS 8,8SilahlaştırılmışEPSS %79splunk · splunk1 Haz 2023
- CVE-2023-2248059Planlayın
KubeOperator is vulnerable to unauthorized access to system API
KritikCVSS 9,8Kavram kanıtıEPSS %67fit2cloud · kubeoperator13 Oca 2023
- CVE-2022-322959Planlayın
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthen
KritikCVSS 9,8SilahlaştırılmışEPSS %66unifiedremote · unified remote6 Şub 2023
- CVE-2023-4824152Planlayın
XWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest service
YüksekCVSS 7,5Kavram kanıtıEPSS %73xwiki · xwiki20 Kas 2023
- CVE-2023-222749Planlayın
Improper Authorization in modoboa/modoboa
KritikCVSS 9,1Kavram kanıtıEPSS %44modoboa · modoboa21 Nis 2023
- CVE-2016-567646Planlayın
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.
YüksekCVSS 7,5SilahlaştırılmışEPSS %54netgear · readynas surveillance31 Ağu 2016
- CVE-2025-2140042Planlayın
Microsoft SharePoint Server Remote Code Execution Vulnerability
YüksekCVSS 8,0İstismar yokEPSS %34microsoft · sharepoint server11 Şub 2025
- CVE-2025-6192842Planlayın
Better Auth: Unauthenticated API key creation through api-key plugin
KritikCVSS 9,3İstismar yokEPSS %18better-auth · better-auth9 Eki 2025
- CVE-2016-335241Planlayın
Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which mak
YüksekCVSS 8,8İstismar yokEPSS %21microsoft · windows 1014 Eyl 2016
- CVE-2019-191241Planlayın
Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerability
KritikCVSS 9,1Kavram kanıtıEPSS %17cisco · sf-220-24 firmware7 Ağu 2019
- CVE-2022-099341Planlayın
SiteGround Security <= 1.2.5 - Authorization Weakness to Authentication Bypass
KritikCVSS 9,8İstismar yokEPSS %8siteground · siteground security19 Nis 2022
- CVE-2021-4233841Planlayın
4MOSAn GCB Doctor - Improper Authorization
KritikCVSS 9,8İstismar yokEPSS %64mosan · gcb doctor19 Kas 2021
- CVE-2019-748941Planlayın
A vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution.
KritikCVSS 9,8Kavram kanıtıEPSS %5sonicwall · email security appliance23 Ara 2019
- CVE-2021-3770541Planlayın
Improper Authorization and Origin Validation Error in OneFuzz
KritikCVSS 10,0İstismar yokEPSS %2microsoft · onefuzz13 Ağu 2021
- CVE-2023-5078040Planlayın
Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
YüksekCVSS 8,8Kavram kanıtıEPSS %17apache · artemis14 Eki 2024
- CVE-2020-174540Planlayın
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.
KritikCVSS 9,8İstismar yokEPSS %5redhat · undertow28 Nis 2020
- CVE-2017-604440Planlayın
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all
KritikCVSS 9,8İstismar yokEPSS %4sierra wireless · airlink raven xe firmware29 Haz 2017
- CVE-2026-2225240Planlayın
LibreChat MCP Stdio Remote Command Execution
KritikCVSS 9,9İstismar yokEPSS %4librechat · librechat12 Oca 2026
- CVE-2016-579940Planlayın
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempt
KritikCVSS 9,8İstismar yokEPSS %4moxa · oncell g3001 firmware23 Ağu 2016
- CVE-2024-3425740Planlayın
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrar
KritikCVSS 9,8Kavram kanıtıEPSS %4totolink · ex1800t firmware8 May 2024
- CVE-2022-2119640Planlayın
Airspan Networks Mimosa Improper Authorization
KritikCVSS 9,8İstismar yokEPSS %4airspan · mimosa management platform18 Şub 2022
- CVE-2017-1674340Planlayın
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1
KritikCVSS 9,8İstismar yokEPSS %3phoenixcontact · fl switch 3005 firmware12 Oca 2018