The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Volume of CVEs assigned to CWE-285 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,435 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28799CRITICAL An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in | May 13, 2021 | 9.8 | 96 | YES | YES |
CVE-2025-29927CRITICAL Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypas | Mar 21, 2025 | 9.1 | 94 | NO | YES |
CVE-2023-32707HIGH In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_us | Jun 1, 2023 | 8.8 | 84 | NO | YES |
CVE-2023-22480CRITICAL KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and be | Jan 14, 2023 | 9.8 | 77 | NO | YES |
CVE-2022-3229CRITICAL Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable a | Feb 6, 2023 | 9.8 | 76 | NO | YES |
CVE-2023-48241HIGH XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that a | Nov 20, 2023 | 7.5 | 73 | NO | YES |
CVE-2016-5676HIGH cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the a | Aug 31, 2016 | 7.5 | 68 | NO | YES |
CVE-2023-2227CRITICAL Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0. | Apr 21, 2023 | 9.1 | 66 | NO | YES |
CVE-2026-10580CRITICAL The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9. | Jun 5, 2026 | 9.8 | 52 | NO | YES |
CVE-2021-39341HIGH The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_ | Nov 1, 2021 | 8.2 | 50 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.