Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-863

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,318
Assigned CVEs
23rd
Commonality Rank
6.7
Avg CVSS
0.6%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-863 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 23, 2001
24 years ago
Most Recent CVE
Jul 24, 2026
0 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

3,318 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-46169CRITICAL
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vu
Dec 5, 20229.899YESYES
CVE-2024-38856CRITICAL
Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the is
Aug 5, 20249.898YESYES
CVE-2023-22518CRITICAL
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to re
Oct 31, 20239.898YESYES
CVE-2023-38035CRITICAL
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administra
Aug 21, 20239.898YESYES
CVE-2019-7192CRITICAL
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to
Dec 5, 20199.898YESYES
CVE-2025-54253CRITICAL
Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this
Aug 5, 202510.096YESNO
CVE-2021-40655HIGH
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php
Sep 24, 20217.596YESYES
CVE-2018-13382HIGH
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7
Jun 4, 20197.595YESYES
CVE-2025-29927CRITICAL
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypas
Mar 21, 20259.194NOYES
CVE-2022-0824HIGH
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
Mar 2, 20228.890NOYES
View all 3,318 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
17%
10%
4.0-4.9
15%
19%
5.0-5.9
17%
16%
6.0-6.9
19%
26%
7.0-7.9
18%
11%
8.0-8.9
11%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
20 CVEs
0.6% of CVEs· 86th percentile
Metasploit
18 CVEs
0.5% of CVEs· 84th percentile
Nuclei
39 CVEs
1.2% of CVEs· 86th percentile
ExploitDB
31 CVEs
0.9% of CVEs· 80th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products