The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Volume of CVEs assigned to CWE-863 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
3,318 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46169CRITICAL Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vu | Dec 5, 2022 | 9.8 | 99 | YES | YES |
CVE-2024-38856CRITICAL Incorrect Authorization vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: through 18.12.14.
Users are recommended to upgrade to version 18.12.15, which fixes the is | Aug 5, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-22518CRITICAL All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to re | Oct 31, 2023 | 9.8 | 98 | YES | YES |
CVE-2023-38035CRITICAL A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administra | Aug 21, 2023 | 9.8 | 98 | YES | YES |
CVE-2019-7192CRITICAL This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to | Dec 5, 2019 | 9.8 | 98 | YES | YES |
CVE-2025-54253CRITICAL Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this | Aug 5, 2025 | 10.0 | 96 | YES | NO |
CVE-2021-40655HIGH An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php | Sep 24, 2021 | 7.5 | 96 | YES | YES |
CVE-2018-13382HIGH An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 | Jun 4, 2019 | 7.5 | 95 | YES | YES |
CVE-2025-29927CRITICAL Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypas | Mar 21, 2025 | 9.1 | 94 | NO | YES |
CVE-2022-0824HIGH Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990. | Mar 2, 2022 | 8.8 | 90 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.