The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,104 vulnerabilities with CWE-863
CVE-2021-27099
MEDIUM
SPIRE < 0.8.5, 0.9.4, 0.10.2, 0.11.3, 0.12.1 - Incorrect Authorization via AWS IID Node Attestor Path Normalization
CVSS 6.8
CVE-2021-26964
HIGH
Aruba AirWave < 8.2.12.0 - Authenticated Privilege Escalation via Web Management Interface
CVSS 7.1
CVE-2021-21725
MEDIUM
ZTE ZXHN H196Q V9.1.0C2 - Authenticated Directory Traversal and Information Disclosure
CVSS 5.7
CVE-2021-26027
MEDIUM
Joomla! 3.0.0-3.9.24 - Incorrect Authorization in Article Category Change
CVSS 5.3
CVE-2021-27225
MEDIUM
Dataiku DSS <8.0.6 - Info Disclosure
CVSS 5.4
CVE-2021-26563
HIGH
Synology DiskStation Manager < 6.2.4-25553 - Incorrect Authorization
CVSS 8.2
CVE-2021-20229
MEDIUM
PostgreSQL < 13.2 - Unauthorized Column Access via SELECT Privilege Escalation
CVSS 4.3
CVE-2021-22113
MEDIUM
Spring Cloud Netflix Zuul < 2.2.6 - Incorrect Authorization via Specially Constructed URLs
CVSS 5.3
CVE-2021-27509
HIGH
Visualware MyConnection Server <11.0b-5382 - Info Disclosure
CVSS 7.5
CVE-2021-21318
MEDIUM
Opencast < 9.2 - Incorrect Authorization via Series Access Control Overwrite
CVSS 5.4
CVE-2021-26753
CRITICAL
NeDi 1.9C - Authenticated PHP Code Injection via System Files Endpoint
CVSS 9.9
CVE-2021-20188
HIGH
podman < 1.7.0 - Incorrect Authorization via Privileged Container File Permissions
CVSS 7.0
CVE-2021-27177
CRITICAL
FiberHome HG6245D Firmware < rp2613 - Unauthenticated Telnet Authentication Bypass via Decoded String
CVSS 9.8
CVE-2021-25777
MEDIUM
JetBrains TeamCity < 2020.2.1 - Incorrect Authorization during Token Removal
CVSS 5.3
CVE-2021-25774
MEDIUM
JetBrains TeamCity < 2020.2.1 - Incorrect Authorization
CVSS 4.3
CVE-2021-21286
HIGH
AVideo Platform <10.2 - Auth Bypass
CVSS 7.7
CVE-2021-21276
CRITICAL
polr < 2.3.0 - Unauthenticated Admin Account Creation via Setup Finish Endpoint
CVSS 9.3
CVE-2021-3337
HIGH
Hide-Thread-Content Plugin through 2021-01-27 for MyBB - Unauthenticated Information Disclosure via Reply or Quote
CVSS 7.5
CVE-2021-26026
HIGH
ACDSee Professional 2021 14.0 1721 - User Mode Write Access Violation via Crafted BMP Image
CVSS 7.8
CVE-2021-26025
HIGH
ACDSee Professional 2021 14.0 1721 - User Mode Write Access Violation via Crafted BMP Image
CVSS 7.8
CVE-2021-1305
HIGH
Cisco SD-WAN vManage Software - Authenticated Authorization Bypass and Information Disclosure
CVSS 8.8
CVE-2021-1270
MEDIUM
Cisco Data Center Network Manager < 11.5(1) - Authenticated Incorrect Authorization
CVSS 6.3
CVE-2021-1269
MEDIUM
Cisco Data Center Network Manager < 11.5(1) - Authenticated Incorrect Authorization
CVSS 6.3
CVE-2021-21013
HIGH
Magento <2.4.1-2.3.6 - Info Disclosure
CVSS 8.1
CVE-2021-1144
HIGH
Cisco Connected Mobile Experiences - Authenticated Password Modification via Incorrect Authorization
CVSS 8.8
Details
Vulnerabilities
3,104
Exploit Likelihood
High