CWE-285
Improper Authorization
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 28 of 28- CVE-2026-49397Medium· 5.3EPSS 0%15 h ago
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking na
go - CVE-2026-47342High· 8.8EPSS 0%17 h ago
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fi
- CVE-2026-42902High· 7.8EPSS 0%18 h ago
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
- CVE-2021-1675High· 7.8KEVEXPLOITEPSS 94%20 h ago
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
- CVE-2021-28799Critical· 10.0KEVEPSS 92%20 h ago
QNAP NAS Improper Authorization Vulnerability
- CVE-2018-13382Critical· 9.1KEVEXPLOITEPSS 87%20 h ago
Fortinet FortiOS and FortiProxy Improper Authorization
- CVE-2026-44208—EPSS 0%21 h ago
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This issue has been patched in versions 15.107.
- CVE-2026-12065Low· 1.821 h ago
A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper authorization in handler for custom url sc
- CVE-2026-47298High· 8.0EPSS 0%21 h ago
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-46668—EPSS 0%1 d ago
SpiceDB: Caveat structures with nested lists can result in improper cache reuse
go - CVE-2026-45503High· 8.1EPSS 0%3 d ago
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
- CVE-2026-45490High· 7.8EPSS 0%3 d ago
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
- CVE-2026-11336Medium· 6.3EPSS 0%3 d ago
A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown function of the file dashboard_page/admin_page.php of the comp
- CVE-2026-11619Medium· 6.3EPSS 0%3 d ago
A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to
- CVE-2026-11461Medium· 6.3EPSS 0%3 d ago
A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to auth
- CVE-2026-46484High· 8.1EPSS 0%3 d ago
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This is
- CVE-2026-46656High· 8.8EPSS 0%3 d ago
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Sessi
- CVE-2026-11521Medium· 6.3EPSS 0%4 d ago
A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/com/alien/bank/management/system/controlle
- CVE-2026-11519Medium· 6.3EPSS 0%4 d ago
A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the component Account Creation Handler. The manip
- CVE-2026-11533Medium· 5.4EPSS 0%4 d ago
A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of the component Student Deleti
- CVE-2026-11440Medium· 6.3EPSS 0%4 d ago
A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This manipulation of the argument project.defaultBranch causes imp
- CVE-2026-11462High· 7.3EPSS 0%4 d ago
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipula
- CVE-2026-11439Medium· 6.3EPSS 0%4 d ago
A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent Project Handler. The manipulation of the argument project.parentId results in im
- CVE-2026-11476Medium· 6.3EPSS 0%4 d ago
A security vulnerability has been detected in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a. Affected by this issue is the function edit-admin of the file controllers/AdminController.php of the component
- CVE-2026-11441Medium· 6.3EPSS 0%4 d ago
A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue of the file /issues/ of the component Pull Request Handler. Such manipulation of the argument issue leads to improper au
- CVE-2026-11500Medium· 5.0EPSS 0%4 d ago
A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key Handler. The manipulation of the argum
- CVE-2026-11438Medium· 6.3EPSS 0%4 d ago
A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromId leads to improper authorization. The at
- CVE-2026-10580Critical· 9.8EPSS 2%7 d ago
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::g
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.