CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,064 vulnerabilities with CWE-863
CVE-2025-24409 HIGH
Adobe Commerce < 2.4.4 - Incorrect Authorization
CVSS 8.2
CVE-2025-24407 HIGH
Adobe Commerce < 2.4.8-beta1 - Incorrect Authorization
CVSS 7.1
CVE-2025-24872 MEDIUM
SAP ABAP Platform - Privilege Escalation
CVSS 4.3
CVE-2025-24869 MEDIUM
SAP NetWeaver Application Server Java - Info Disclosure
CVSS 4.3
CVE-2025-24200 MEDIUM KEV
iPadOS < 15.8.4, < 16.7.11, < 17.7.5, < 18.3.1 - Authorization Bypass via USB Restricted Mode
CVSS 6.1
CVE-2025-23419 MEDIUM
F5 NGINX 1.11.4-1.26.2 and NGINX Plus R28-R31 - Incorrect Authorization via TLS Session Resumption
CVSS 4.3
CVE-2025-24860 MEDIUM
Apache Cassandra <4.0.15, <4.1.7 - Auth Bypass
CVSS 5.4
CVE-2025-24500 HIGH
Broadcom Symantec Privileged Access Management 3.4.6-4.1.7 and 4.2.0 - Unauthenticated Information Disclosure
CVE-2025-24099 MEDIUM
macOS < 13.7.3, < 14.7.3, < 15.3 - Privilege Escalation
CVSS 5.1
CVE-2025-24479 HIGH
Rockwell FactoryTalk View ME <V15 - Local Privileged Command Execution
CVE-2025-23054 MEDIUM
HPE Aruba Networking Fabric Composer 7.0.0-7.1.0 - Authenticated Incorrect Authorization
CVSS 6.5
CVE-2025-23053 MEDIUM
HPE Aruba Networking Fabric Composer 7.0.0-7.1.0 - Authenticated Privilege Escalation via Web Management Interface
CVSS 6.5
CVE-2025-0781 HIGH
simgear < 2020.3.19 - Unauthenticated Arbitrary File Write via Nasal Script Sandbox Bypass
CVSS 8.6
CVE-2025-24141 LOW
iPadOS < 18.3 - Unauthenticated Photos Access via Locked App Bypass
CVSS 3.3
CVE-2025-24121 LOW
macOS < 13.7.3, < 14.7.3, < 15.3 - Unauthorized File System Modification
CVSS 3.3
CVE-2025-24114 MEDIUM
macOS < 13.7.3, < 14.7.3, < 15.3 - Unauthorized File System Modification
CVSS 5.5
CVE-2025-24401 MEDIUM
Jenkins Folder-based Authorization Strategy Plugin < 217.vd5b_18537403e - Incorrect Authorization
CVSS 6.8
CVE-2025-24400 MEDIUM
Jenkins Eiffel Broadcaster Plugin 2.8.0-2.10.2 - Incorrect Authorization via Credential ID Cache Key
CVSS 4.3
CVE-2025-24397 MEDIUM
Jenkins GitLab Plugin < 1.9.6 - Incorrect Authorization via Global Item/Configure Permission
CVSS 4.3
CVE-2025-21570 MEDIUM
Oracle Life Sciences Argus Safety 8.2.3 - Unauthenticated Incorrect Authorization in Login Component
CVSS 6.1
CVE-2025-21569 MEDIUM
Oracle Hyperion Data Relationship Management 11.2.19.0.000 - Incorrect Authorization in Web Services
CVSS 6.6
CVE-2025-21568 MEDIUM
Oracle Hyperion Data Relationship Management 11.2.19.0.000 - Unauthorized Data Access via Access and Security Component
CVSS 4.5
CVE-2025-21567 MEDIUM
MySQL Server < 9.1.0 - Unauthorized Data Access via Privilege Misconfiguration
CVSS 4.3
CVE-2025-21565 HIGH
Oracle Agile PLM Framework 9.3.6 - Unauthenticated Incorrect Authorization via HTTP
CVSS 7.5
CVE-2025-21563 MEDIUM
Oracle PeopleSoft Enterprise CC Common Application Objects 9.2 - Incorrect Authorization in Run Control Management
CVSS 4.3
Details
Vulnerabilities 3,064
Exploit Likelihood High