CWE-863 · 3.387 kayıt
Incorrect Authorization
Bu sınıftaki CVE’ler
3.410 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2023-22518Silahlaştırılmış | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.atlassian · confluence data center · CWE-863 | Kritik9,8 | KEV | %100,0 | 31 Eki 2023 |
99Hemen | CVE-2023-38035Silahlaştırılmış | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass aivanti · mobileiron sentry · CWE-863 | Kritik9,8 | KEV | %100,0 | 21 Ağu 2023 |
99Hemen | CVE-2024-38856Silahlaştırılmış | Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering codeapache · ofbiz · CWE-863 | Kritik9,8 | KEV | %99,4 | 5 Ağu 2024 |
96Hemen | CVE-2025-54253Silahlaştırılmış | Adobe Experience Manager | Incorrect Authorization (CWE-863)adobe · experience manager forms · CWE-863 | Kritik10,0 | KEV | %88,0 | 5 Ağu 2025 |
95Hemen | CVE-2019-7192Silahlaştırılmış | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.qnap · photo station · CWE-863 | Kritik9,8 | KEV | %88,1 | 5 Ara 2019 |
92Hemen | CVE-2026-71362Silahlaştırılmış | Adobe Commerce | Incorrect Authorization (CWE-863)adobe · commerce · CWE-863 | Kritik9,1 | KEV | %87,5 | 11 Ağu 2026 |
86Hemen | CVE-2021-40655Silahlaştırılmış | An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.dlink · dir-605l firmware · CWE-863 | Yüksek7,5 | KEV | %86,7 | 24 Eyl 2021 |
85Hemen | CVE-2018-13382Silahlaştırılmış | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 tfortinet · fortiproxy · CWE-863 | Yüksek7,5 | KEV | %81,7 | 4 Haz 2019 |
70Bu hafta | CVE-2023-24880Silahlaştırılmış | Windows SmartScreen Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-863 | Orta4,4 | KEV | %78,0 | 14 Mar 2023 |
68Bu hafta | CVE-2021-3560Silahlaştırılmış | It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestorpolkit project · polkit · CWE-863 | Yüksek7,8 | KEV | %23,7 | 16 Şub 2022 |
68Bu hafta | CVE-2026-42016Silahlaştırılmış | Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalationjfrog · artifactory · CWE-863 | Yüksek8,8 | KEV | %8,6 | 27 Tem 2026 |
64Bu hafta | CVE-2024-6782Silahlaştırılmış | Calibre Remote Code Executioncalibre · calibre · CWE-863 | Kritik9,8 | — | %84,1 | 6 Ağu 2024 |
64Bu hafta | CVE-2025-21479Silahlaştırılmış | Incorrect Authorization in Graphicsqualcomm · aqt1000 firmware · CWE-863 | Yüksek8,6 | KEV | %0,8 | 3 Haz 2025 |
64Bu hafta | CVE-2025-21480Silahlaştırılmış | Incorrect Authorization in Graphics Windowsqualcomm · aqt1000 firmware · CWE-863 | Yüksek8,6 | KEV | %0,5 | 3 Haz 2025 |
63Bu hafta | CVE-2020-13957Kavram kanıtı | Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for apache · solr · CWE-863 | Kritik9,8 | — | %79,3 | 13 Eki 2020 |
63Bu hafta | CVE-2023-21715Silahlaştırılmış | Microsoft Publisher Security Feature Bypass Vulnerabilitymicrosoft · 365 apps · CWE-863 | Yüksek7,3 | KEV | %12,0 | 14 Şub 2023 |
61Bu hafta | CVE-2021-30533Silahlaştırılmış | Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrigoogle · chrome · CWE-863 | Orta6,5 | KEV | %16,6 | 7 Haz 2021 |
61Bu hafta | CVE-2024-21287Silahlaştırılmış | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension).oracle · agile product lifecycle management · CWE-863 | Yüksek7,5 | KEV | %1,7 | 18 Kas 2024 |
57Planlayın | CVE-2019-7304Kavram kanıtı | Local privilege escalation via snapd socketcanonical · snapd · CWE-863 | Kritik9,8 | — | %60,8 | 23 Nis 2019 |
56Planlayın | CVE-2021-45466İstismar yok | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to acontrol-webpanel · webpanel · CWE-863 | Kritik9,8 | — | %55,3 | 26 Ara 2022 |
55Planlayın | CVE-2025-24200Silahlaştırılmış | An authorization issue was addressed with improved state management.apple · ipados · CWE-863 | Orta6,1 | KEV | %4,5 | 10 Şub 2025 |
54Planlayın | CVE-2023-35166İstismar yok | Privilege escalation (PR) from account through TipsPanelxwiki · xwiki · CWE-863 | Yüksek8,8 | — | %62,2 | 20 Haz 2023 |
53Planlayın | CVE-2010-2965İstismar yok | The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with frockwellautomation · 1756-enbt\/a firmware · CWE-863 | Kritik9,8 | — | %47,4 | 5 Ağu 2010 |
52Planlayın | CVE-2023-34051Kavram kanıtı | VMware Aria Operations for Logs contains an authentication bypass vulnerability.vmware · aria operations for logs · CWE-863 | Kritik9,8 | — | %44,7 | 20 Eki 2023 |
52Planlayın | CVE-2025-55177Silahlaştırılmış | Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25whatsapp · whatsapp · CWE-863 | Orta5,4 | KEV | %4,3 | 29 Ağu 2025 |
- CVE-2023-2251899Hemen
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100atlassian · confluence data center31 Eki 2023
- CVE-2023-3803599Hemen
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100ivanti · mobileiron sentry21 Ağu 2023
- CVE-2024-3885699Hemen
Apache OFBiz: Unauthenticated endpoint could allow execution of screen rendering code
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · ofbiz5 Ağu 2024
- CVE-2025-5425396Hemen
Adobe Experience Manager | Incorrect Authorization (CWE-863)
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %88adobe · experience manager forms5 Ağu 2025
- CVE-2019-719295Hemen
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %88qnap · photo station5 Ara 2019
- CVE-2026-7136292Hemen
Adobe Commerce | Incorrect Authorization (CWE-863)
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %88adobe · commerce11 Ağu 2026
- CVE-2021-4065586Hemen
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %87dlink · dir-605l firmware24 Eyl 2021
- CVE-2018-1338285Hemen
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 t
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %82fortinet · fortiproxy4 Haz 2019
- CVE-2023-2488070Bu hafta
Windows SmartScreen Security Feature Bypass Vulnerability
OrtaCVSS 4,4KEVSilahlaştırılmışEPSS %78microsoft · windows 10 160714 Mar 2023
- CVE-2021-356068Bu hafta
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %24polkit project · polkit16 Şub 2022
- CVE-2026-4201668Bu hafta
Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %9jfrog · artifactory27 Tem 2026
- CVE-2024-678264Bu hafta
Calibre Remote Code Execution
KritikCVSS 9,8SilahlaştırılmışEPSS %84calibre · calibre6 Ağu 2024
- CVE-2025-2147964Bu hafta
Incorrect Authorization in Graphics
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %1qualcomm · aqt1000 firmware3 Haz 2025
- CVE-2025-2148064Bu hafta
Incorrect Authorization in Graphics Windows
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %0qualcomm · aqt1000 firmware3 Haz 2025
- CVE-2020-1395763Bu hafta
Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for
KritikCVSS 9,8Kavram kanıtıEPSS %79apache · solr13 Eki 2020
- CVE-2023-2171563Bu hafta
Microsoft Publisher Security Feature Bypass Vulnerability
YüksekCVSS 7,3KEVSilahlaştırılmışEPSS %12microsoft · 365 apps14 Şub 2023
- CVE-2021-3053361Bu hafta
Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restri
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %17google · chrome7 Haz 2021
- CVE-2024-2128761Bu hafta
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension).
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %2oracle · agile product lifecycle management18 Kas 2024
- CVE-2019-730457Planlayın
Local privilege escalation via snapd socket
KritikCVSS 9,8Kavram kanıtıEPSS %61canonical · snapd23 Nis 2019
- CVE-2021-4546656Planlayın
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to a
KritikCVSS 9,8İstismar yokEPSS %55control-webpanel · webpanel26 Ara 2022
- CVE-2025-2420055Planlayın
An authorization issue was addressed with improved state management.
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %4apple · ipados10 Şub 2025
- CVE-2023-3516654Planlayın
Privilege escalation (PR) from account through TipsPanel
YüksekCVSS 8,8İstismar yokEPSS %62xwiki · xwiki20 Haz 2023
- CVE-2010-296553Planlayın
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with f
KritikCVSS 9,8İstismar yokEPSS %47rockwellautomation · 1756-enbt\/a firmware5 Ağu 2010
- CVE-2023-3405152Planlayın
VMware Aria Operations for Logs contains an authentication bypass vulnerability.
KritikCVSS 9,8Kavram kanıtıEPSS %45vmware · aria operations for logs20 Eki 2023
- CVE-2025-5517752Planlayın
Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25
OrtaCVSS 5,4KEVSilahlaştırılmışEPSS %4whatsapp · whatsapp29 Ağu 2025