CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,070 vulnerabilities with CWE-863
CVE-2024-9098 MEDIUM
lunary < 1.4.30 - Incorrect Authorization via User Invitation Endpoint
CVSS 6.1
CVE-2024-7039 MEDIUM
open-webui v0.3.8 - Authenticated Administrator Deletion via API Endpoint
CVSS 6.7
CVE-2024-10275 HIGH
lunary-ai/lunary <1.5.5 - Privilege Escalation
CVSS 7.3
CVE-2024-10273 MEDIUM
lunary-ai/lunary v1.5.0 - Privilege Escalation
CVSS 6.5
CVE-2024-10109 HIGH
mintplex-labs/anything-llm <5c40419 - Info Disclosure
CVSS 8.3
CVE-2024-7296 LOW
GitLab 16.5-17.7.6, 17.8-17.8.4, 17.9-17.9.1 - Incorrect Authorization in Membership Approval
CVSS 2.7
CVE-2024-55592 LOW
FortiSIEM 5.3.0-7.2.4 - Authenticated Incorrect Authorization via Crafted HTTP Requests
CVSS 3.8
CVE-2024-45328 HIGH
FortiSandbox <4.4.7 - Privilege Escalation
CVSS 7.8
CVE-2024-2321 MEDIUM
WSO2 API Manager and Identity Server - Incorrect Authorization via Refresh Token
CVSS 5.6
CVE-2024-5705 HIGH
Pentaho Business Analytics Server <10.2.0.0-9.3.0.9 - Privilege Esc...
CVSS 8.8
CVE-2024-45081 MEDIUM
IBM Cognos Controller 11.0.0-11.0.1 FP3 & 11.1.0 - Privilege Escala...
CVSS 6.5
CVE-2024-39328 MEDIUM
Atos Eviden IDRA & IDCA <2.7.0 - Privilege Escalation
CVSS 6.8
CVE-2024-57969 MEDIUM
MISP < 2.4.198 - Incorrect Authorization in Attribute Search
CVSS 4.3
CVE-2024-54916 MEDIUM
Telegram Android APK <11.7.0 - Privilege Escalation
CVSS 6.8
CVE-2024-57434 HIGH
macrozheng mall-tiny 1.0.1 - Incorrect Access Control
CVSS 8.8
CVE-2024-23929 HIGH
Pioneer DMH-WT7600NEX Firmware - Authenticated Arbitrary File Write via Telematics Path Traversal
CVSS 7.3
CVE-2024-57438 MEDIUM
RuoYi 4.8.0 - Authenticated Privilege Escalation via Insecure Role Assignment
CVSS 5.4
CVE-2024-41140 HIGH
ManageEngine Applications Manager <= 174000 - Incorrect Authorization in Update User Function
CVSS 8.1
CVE-2024-54530 CRITICAL
Apple iPadOS < 18.2 - Incorrect Authorization in Password Autofill
CVSS 9.1
CVE-2024-54512 CRITICAL
iPadOS < 18.2 - Unauthorized User Fingerprinting via System Binary
CVSS 9.1
CVE-2024-54488 MEDIUM
iPhone OS < 18.2 - Unauthenticated Hidden Photos Album Access
CVSS 5.3
CVE-2024-44172 LOW
macOS < 13.7.3, < 14.7.3, < 15 - Unprotected User Data Exposure via Log Entry Redaction
CVSS 3.3
CVE-2024-22316 MEDIUM
IBM Sterling File Gateway <6.1.2.5, <6.2.0.1 - Privilege Escalation
CVSS 4.3
CVE-2024-42013 MEDIUM
GRAU DATA Blocky <3.1 - Privilege Escalation
CVSS 6.4
CVE-2024-51417 MEDIUM
System.Linq.Dynamic.Core < 1.6.0 - Unauthenticated Remote Property Access via Reflection
CVSS 6.4
Details
Vulnerabilities 3,070
Exploit Likelihood High