CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,064 vulnerabilities with CWE-863
CVE-2025-43561 CRITICAL
ColdFusion 2025.1 2023.13 2021.19 and earlier - Authenticated Remote Code Execution via Authorization Bypass
CVSS 9.1
CVE-2025-4646 HIGH
Centreon web <24.04.10-24.10.4 - Privilege Escalation
CVSS 7.2
CVE-2025-27696 HIGH
Apache Superset <= 4.1.1 - Authenticated Ownership Takeover via Dashboard Chart or Dataset
CVSS 8.8
CVE-2025-31227 MEDIUM
iPadOS < 18.5 - Unauthorized Access to Deleted Call Recordings
CVSS 4.6
CVE-2025-30440 MEDIUM
macOS < 13.7.6, < 14.7.6, < 15.5 - ASLR Bypass via Incorrect Authorization
CVSS 5.5
CVE-2025-46744 LOW
SEL Blueframe OS < 1.12.0 - Authenticated User Account Metadata Tampering
CVSS 2.7
CVE-2025-29827 CRITICAL
Azure Automation - Privilege Escalation via Improper Authorization
CVSS 9.9
CVE-2025-26842 HIGH
Znuny < 7.1.3 - Incorrect Authorization in CommunicationLog
CVSS 7.5
CVE-2025-46265 HIGH
F5OS-A and F5OS-C >=1.6.0 <1.6.2 - Authenticated Incorrect Authorization
CVSS 8.8
CVE-2025-36546 HIGH
F5OS-A 1.5.1-1.5.3 and F5OS-C 1.6.0-1.6.2 - Incorrect Authorization via SSH Key-Based Authentication
CVSS 8.1
CVE-2025-3476 CRITICAL
OpenText Operations Bridge Manager - Privilege Escalation
CVE-2025-3272 MEDIUM
OpenText Operations Bridge Manager <24.4 - Auth Bypass
CVE-2025-3609 MEDIUM
Reales WP STPT <2.1.2 - Privilege Escalation
CVSS 5.3
CVE-2025-3879 MEDIUM
HashiCorp Vault - Incorrect Authorization via Azure Auth Method Bound Location Bypass
CVSS 6.6
CVE-2025-46569 HIGH
Open Policy Agent < 1.4.0 - Rego Injection via HTTP Data API Path
CVE-2025-23244 HIGH
NVIDIA GPU Display Driver - Privilege Escalation
CVSS 7.8
CVE-2025-32971 LOW
XWiki 4.5.1-15.10.12, 16.0.0-rc-1-16.4.3, 16.5.0-rc-1-16.8.0-rc-1 - Incorrect Authorization in Solr Script Service
CVSS 3.8
CVE-2025-40619 HIGH
Bookgy - Unauthenticated Incorrect Authorization
CVSS 7.5
CVE-2025-3963 HIGH
withstars Books-Management-System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-3960 HIGH
withstars Books-Management-System 1.0 - Info Disclosure
CVSS 7.3
CVE-2025-3647 MEDIUM
Moodle < 4.1.18 - Incorrect Authorization in Cohort Data Access
CVSS 4.3
CVE-2025-3645 MEDIUM
Moodle < 4.1.18 - Incorrect Authorization in Messaging Web Service
CVSS 4.3
CVE-2025-3644 MEDIUM
Moodle < 4.1.18 - Incorrect Authorization in Course Section Deletion
CVSS 4.3
CVE-2025-3861 MEDIUM
Prevent Direct Access - Protect WordPress Files <2.8.8.2 - Privileg...
CVSS 5.4
CVE-2025-46544 MEDIUM
Sherpa Orchestrator 141851 - Privilege Escalation
CVSS 6.4
Details
Vulnerabilities 3,064
Exploit Likelihood High