The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,108 vulnerabilities with CWE-863
CVE-2017-10379
MEDIUM
MySQL < 5.5.57, 5.6.37, 5.7.19 - Authenticated Unauthorized Data Access via Client Programs
CVSS 6.5
CVE-2017-9653
CRITICAL
OSIsoft PI Integrator <2016 R2 - Privilege Escalation
CVSS 9.8
CVE-2017-8633
HIGH
Windows Error Reporting - Elevation of Privilege via Incorrect Authorization
CVSS 7.5
CVE-2017-9855
CRITICAL
SMA Solar Technology - Privilege Escalation
CVSS 9.8
CVE-2017-6672
HIGH
Cisco ASR 5000 Series Software - Unauthenticated Access Control List Bypass
CVSS 7.5
CVE-2017-7512
CRITICAL
Red Hat 3scale <2.0.0 - Auth Bypass
CVSS 9.8
CVE-2017-10805
HIGH
Odoo 8.0, 9.0, 10.0 - Authenticated OAuth Session Hijacking via Incorrect Access Control
CVSS 8.8
CVE-2017-8907
HIGH
Atlassian Bamboo <5.15.7-6.0.1 - RCE
CVSS 8.8
CVE-2017-9378
MEDIUM
BigTree CMS <4.2.18 - Info Disclosure
CVSS 6.5
CVE-2017-2306
HIGH
Juniper Networks Junos Space <16.1R1 - Code Injection
CVSS 8.8
CVE-2017-2305
HIGH
Juniper Networks Junos Space <16.1R1 - Privilege Escalation
CVSS 8.8
CVE-2017-7505
HIGH
Foreman <1.5 - Privilege Escalation
CVSS 8.8
CVE-2017-4915
HIGH
VMware Workstation Pro/Player - Privilege Escalation
CVSS 7.8
CVE-2017-0894
MEDIUM
Nextcloud Server <11.0.3 - Info Disclosure
CVSS 4.3
CVE-2017-3817
MEDIUM
Cisco UCS Director <6.0 - Info Disclosure
CVSS 4.3
CVE-2017-0881
MEDIUM
Zulip <1.4.3 - Privilege Escalation
CVSS 4.3
CVE-2017-5618
HIGH
GNU screen < 4.5.1 - Unauthenticated Arbitrary File Write via Logfile Permissions
CVSS 7.8
CVE-2017-6377
HIGH
Drupal 8.2.x < 8.2.7 - Incorrect Authorization in Private File Editor
CVSS 7.5
CVE-2017-6816
MEDIUM
WordPress < 4.7.3 - Unintended File Deletion via Plugin Deletion Functionality
CVSS 4.9
CVE-2017-6590
MEDIUM
Ubuntu Linux - Unauthenticated Local File Access and Command Execution via Network Manager Applet
CVSS 6.3
CVE-2017-3801
HIGH
Cisco UCS Director <6.0.1 - Privilege Escalation
CVSS 8.8
CVE-2016-20075
HIGH
WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
CVSS 8.8
CVE-2016-20005
CRITICAL
REST/JSON Project 7.x-1.x - Auth Bypass
CVSS 9.8
CVE-2016-20004
CRITICAL
REST/JSON Project 7.x-1.x - Auth Bypass
CVSS 9.8
CVE-2016-20002
CRITICAL
REST/JSON Project 7.x-1.x - Auth Bypass
CVSS 9.8
Details
Vulnerabilities
3,108
Exploit Likelihood
High