Fallos del tipo CWE-285

1294 resultados
CVE-2023-0610MEDIUMImproper Authorization in wallabag/wallabagEPSS 0.4%CVE-2023-3574MEDIUMImproper Authorization in pimcore/customer-data-frameworkEPSS 0.4%CVE-2026-28448MEDIUMOpenClaw 2026.1.29 < 2026.2.1 - Authorization Bypass in Twitch Plugin allowFrom Access ControlEPSS 0.4%CVE-2024-46942CRITICALIn OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entriesEPSS 0.4%CVE-2024-39411MEDIUMAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.4%CVE-2024-39413MEDIUMAn unauthorized user can export the Invoiced Sales ReportEPSS 0.4%CVE-2024-39415MEDIUMAn unauthorized user can export the Tax Sales ReportEPSS 0.4%CVE-2024-39417MEDIUMAn unauthorized user can export the Shipping ReportEPSS 0.4%CVE-2024-39416MEDIUMUnauthorized user can export Orders Sale ReportEPSS 0.4%CVE-2026-3185MEDIUMfeiyuchuixue sz-boot-parent API Endpoint sys-message authorizationEPSS 0.4%CVE-2024-23670HIGHAn improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 alloEPSS 0.4%CVE-2024-23667HIGHAn improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 alloEPSS 0.4%CVE-2025-4017MEDIUM20120630 Novel-Plus LogController.java list improper authorizationEPSS 0.4%CVE-2023-33183LOWError in calendar when booking an appointment reveals the full path of the websiteEPSS 0.4%CVE-2025-12283MEDIUMcode-projects Client Details System authorizationEPSS 0.4%CVE-2025-12288MEDIUMBdtask Pharmacy Management System User Profile edit_user authorizationEPSS 0.4%CVE-2025-0849MEDIUMCampCodes School Management Software Staff edit-staff improper authorizationEPSS 0.4%CVE-2024-21761LOWAn improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to dowEPSS 0.4%CVE-2024-39412MEDIUMAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.4%CVE-2025-2589MEDIUMcode-projects Human Resource Management System Account.go Index improper authorizationEPSS 0.4%