CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,064 vulnerabilities with CWE-863
CVE-2025-49825 CRITICAL
Teleport <= 17.5.1 - Unauthenticated Remote Authentication Bypass
CVSS 9.8
CVE-2025-3880 MEDIUM
Opinion Stage Poll, Survey & Quiz Maker <= 19.9.0 - Authenticated Data Modification via Capability Check
CVSS 4.3
CVE-2025-49586 HIGH
XWiki 7.3-16.4.6 - Authenticated Remote Code Execution via App Within Minutes Application Edit
CVSS 8.8
CVE-2025-6003 MEDIUM
WordPress SSO <*.5.3 - Info Disclosure
CVSS 5.3
CVE-2025-48446 HIGH
Drupal Commerce Alphabank Redirect <1.0.3 - Auth Bypass
CVSS 8.8
CVE-2025-48445 HIGH
Drupal Commerce Eurobank (Redirect) <2.1.1 - Functionality Misuse
CVSS 8.8
CVE-2025-4128 LOW
Mattermost 9.11.0-9.11.13 and 10.5.0-10.5.4 - Incorrect Authorization via Teams API
CVSS 3.1
CVE-2025-36578 MEDIUM
Dell Wyse Management Suite < 5.2 - Incorrect Authorization
CVSS 6.8
CVE-2025-40568 MEDIUM
RUGGEDCOM RST2428P - Path Traversal
CVSS 4.3
CVE-2025-40567 MEDIUM
RUGGEDCOM RST2428P - Path Traversal
CVSS 6.5
CVE-2025-40670 HIGH
TCMAN GIM v11 - Unauthenticated Incorrect Authorization via /PC/frmGestionUser.aspx/updateUser
CVSS 8.8
CVE-2025-40669 MEDIUM
TCMAN GIM v11 - Unauthenticated Incorrect Authorization via POST Request to /PC/Options.aspx
CVSS 6.5
CVE-2025-40668 MEDIUM
TCMAN GIM v11 - Incorrect Authorization via Password Change Endpoint
CVSS 6.5
CVE-2025-49599 MEDIUM
Huawei EG8141A5 <V5R019C00S100 - Privilege Escalation
CVSS 4.1
CVE-2025-48935 CRITICAL
Deno 2.2.0-2.2.5 - Incorrect Authorization via ATTACH DATABASE Statement
CVSS 9.1
CVE-2025-48888 MEDIUM
Deno <2.1.13, <2.2.13, <2.3.2 - Info Disclosure
CVSS 5.3
CVE-2025-21479 HIGH KEV
Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via Unauthorized GPU Micronode Command Execution
CVSS 8.6
CVE-2025-21480 HIGH KEV
Qualcomm AQT1000 and FastConnect Firmware - Memory Corruption via Unauthorized GPU Micronode Command Execution
CVSS 8.6
CVE-2025-3260 HIGH
Grafana API <v2alpha1 - Auth Bypass
CVSS 8.3
CVE-2025-20674 CRITICAL
OpenWrt - Unauthenticated Arbitrary Packet Injection via Missing Permission Check
CVSS 9.8
CVE-2025-48948 MEDIUM
navidrome < 0.56.0 - Authenticated Incorrect Authorization via Transcoding Configuration
CVSS 6.5
CVE-2025-3611 LOW
Mattermost 9.11.0-9.11.12 10.5.0-10.5.3 10.7.0 - Authenticated Incorrect Authorization via Team API Endpoint
CVSS 3.1
CVE-2025-1792 LOW
Mattermost <10.7.0, <10.5.3, <9.11.12 - Info Disclosure
CVSS 3.1
CVE-2025-48881 HIGH
Valtimo <12.12.0.RELEASE - Info Disclosure
CVSS 8.3
CVE-2025-48757 CRITICAL
Lovable <2025-04-15 - Info Disclosure
CVSS 9.3
Details
Vulnerabilities 3,064
Exploit Likelihood High