Fallos del tipo CWE-285

1280 resultados
CVE-2025-29927CRITICALAuthorization Bypass in Next.js MiddlewareEPSS 98.4%CVE-2021-28799CRITICALImproper Authorization Vulnerability in HBS 3 (Hybrid Backup Sync)EPSS 78.4%KEVCVE-2023-32707HIGH‘edit_user’ Capability Privilege EscalationEPSS 73.5%CVE-2023-48241HIGHXWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest serviceEPSS 72.8%CVE-2023-22480HIGHKubeOperator is vulnerable to unauthorized access to system APIEPSS 66.8%CVE-2022-3229CRITICALBecause the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenEPSS 66.4%CVE-2023-2227CRITICALImproper Authorization in modoboa/modoboaEPSS 43.8%CVE-2024-45387CRITICALApache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_commentsEPSS 41.8%CVE-2019-1898MEDIUMCisco RV110W, RV130W, and RV215W Routers Unauthenticated syslog File Access VulnerabilityEPSS 41.0%CVE-2025-21400HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 29.8%CVE-2024-27937MEDIUMglpi Users emails enumerationEPSS 26.8%CVE-2021-39341HIGHOptinMonster <= 2.6.4 Unprotected REST-API EndpointsEPSS 23.3%CVE-2024-3013MEDIUMTeledyne FLIR AX8 User Registration test_login.php improper authorizationEPSS 23.0%CVE-2025-61928CRITICALBetter Auth: Unauthenticated API key creation through api-key pluginEPSS 18.0%CVE-2019-1912CRITICALCisco Small Business 220 Series Smart Switches Authentication Bypass VulnerabilityEPSS 17.0%CVE-2023-50780HIGHApache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeansEPSS 16.5%CVE-2025-20125CRITICALCisco Identity Services Engine Insufficient Authorization Bypass VulnerabilityEPSS 14.5%CVE-2025-2359MEDIUMD-Link DIR-823G DDNS Service HNAP1 SetDDNSSettings improper authorizationEPSS 14.0%CVE-2017-11398A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow EPSS 8.3%CVE-2022-0993HIGHSiteGround Security <= 1.2.5 - Authorization Weakness to Authentication BypassEPSS 7.5%