CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,734)
page 181 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-48472 | Hig | 0.00 | 8.1 | 0.00 | May 29, 2025 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that the user is disabling notifications for the mailbox to which they already have access. Moreover, the code explicitly implements functionality that if the user… | ||
| CVE-2025-48373 | Cri | 0.00 | 9.1 | 0.00 | May 22, 2025 | Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different panels based on their role. Prior to version 1.0.1, this implementation poses a serious security risk because it assumes that the… | ||
| CVE-2025-47930 | Med | 0.00 | 5.3 | 0.00 | May 16, 2025 | Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A… | ||
| CVE-2025-32796 | Med | 0.00 | 6.5 | 0.00 | Apr 18, 2025 | Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the API, even though the web UI button for this action is disabled and normal users are not permitted to… | ||
| CVE-2024-7039 | 0.00 | — | 0.01 | Mar 20, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |||
| CVE-2024-10109 | Hig | 0.00 | 8.3 | 0.01 | Mar 20, 2025 | A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, leading to potential API key… | ||
| CVE-2025-26532 | Low | 0.00 | 3.1 | 0.00 | Feb 24, 2025 | Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored. | ||
| CVE-2025-26531 | Low | 0.00 | 3.1 | 0.00 | Feb 24, 2025 | Insufficient capability checks made it possible to disable badges a user does not have permission to access. | ||
| CVE-2025-26526 | Med | 0.00 | 6.5 | 0.00 | Feb 24, 2025 | Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities. | ||
| CVE-2025-0781 | Hig | 0.00 | 8.6 | 0.00 | Jan 28, 2025 | An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level. | ||
| CVE-2025-24400 | Med | 0.00 | 4.3 | 0.00 | Jan 22, 2025 | Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event… | ||
| CVE-2025-24397 | Med | 0.00 | 4.3 | 0.00 | Jan 22, 2025 | An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in… | ||
| CVE-2024-52584 | Med | 0.00 | 5.4 | 0.00 | Nov 18, 2024 | Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view or edit the grade for any submission ID, even if they are not a CA for the class that has the submission. The endpoints only… | ||
| CVE-2024-52518 | Med | 0.00 | 4.4 | 0.01 | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is recommended that the Nextcloud… | ||
| CVE-2024-43433 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users. | ||
| CVE-2024-48925 | Non | 0.00 | 0.0 | 0.00 | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users… | ||
| CVE-2024-47172 | Med | 0.00 | 5.4 | 0.00 | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership resource on the CVAT instance. The information exposed in… | ||
| CVE-2024-47077 | Med | 0.00 | 6.5 | 0.00 | Sep 27, 2024 | authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were… | ||
| CVE-2024-3033 | Cri | 0.00 | 9.4 | 0.01 | Jun 6, 2024 | An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, including resetting the database… | ||
| CVE-2024-32983 | Hig | 0.00 | 8.2 | 0.00 | Jun 3, 2024 | Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents of signed activities and… |
- risk 0.00cvss 8.1epss 0.00
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that the user is disabling notifications for the mailbox to which they already have access. Moreover, the code explicitly implements functionality that if the user…
- risk 0.00cvss 9.1epss 0.00
Schule is open-source school management system software. The application relies on client-side JavaScript (index.js) to redirect users to different panels based on their role. Prior to version 1.0.1, this implementation poses a serious security risk because it assumes that the…
- risk 0.00cvss 5.3epss 0.00
Zulip is an open-source team chat application. Starting in version 10.0 and prior to version 10.3, the "Who can create public channels" access control mechanism can be circumvented by creating a private or web-public channel, and then changing the channel privacy to public. A…
- risk 0.00cvss 6.5epss 0.00
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the API, even though the web UI button for this action is disabled and normal users are not permitted to…
- CVE-2024-7039Mar 20, 2025risk 0.00cvss —epss 0.01
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.00cvss 8.3epss 0.01
A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them to modify the model's API key and base path, leading to potential API key…
- risk 0.00cvss 3.1epss 0.00
Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.
- risk 0.00cvss 3.1epss 0.00
Insufficient capability checks made it possible to disable badges a user does not have permission to access.
- risk 0.00cvss 6.5epss 0.00
Separate Groups mode restrictions were not factored into permission checks before allowing viewing or deletion of responses in Feedback activities.
- risk 0.00cvss 8.6epss 0.00
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
- risk 0.00cvss 4.3epss 0.00
Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event…
- risk 0.00cvss 4.3epss 0.00
An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in…
- risk 0.00cvss 5.4epss 0.00
Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in version 3.0.1 where CAs can view or edit the grade for any submission ID, even if they are not a CA for the class that has the submission. The endpoints only…
- risk 0.00cvss 4.4epss 0.01
Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is recommended that the Nextcloud…
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.
- risk 0.00cvss 0.0epss 0.00
Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users…
- risk 0.00cvss 5.4epss 0.00
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain information about any project, task, job or membership resource on the CVAT instance. The information exposed in…
- risk 0.00cvss 6.5epss 0.00
authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user against any other proxy provider. Also, a user can steal an access token they were…
- risk 0.00cvss 9.4epss 0.01
An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, including resetting the database…
- risk 0.00cvss 8.2epss 0.00
Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing them, allowing threat actors to spoof the contents of signed activities and…