The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,070 vulnerabilities with CWE-863
CVE-2024-57032
CRITICAL
WeGIA < 3.2.0 - Privilege Escalation
CVSS 9.8
CVE-2024-53553
CRITICAL
OPEXUS FOIAXPRESS PUBLIC ACCESS LINK 11.1.0 - Unauthenticated Authentication Bypass
CVSS 9.1
CVE-2024-57683
MEDIUM
D-Link DIR-816 Firmware 1.10CNB05 - Unauthenticated Incorrect Authorization
CVSS 4.3
CVE-2024-57681
MEDIUM
D-Link DIR-816 Firmware 816A2_FWv1.10CNB05_R1B011D88210 - Unauthenticated Incorrect Authorization via form2alg.cgi
CVSS 5.3
CVE-2024-57680
MEDIUM
D-Link DIR-816 Firmware - Unauthenticated Port Trigger Manipulation via form2PortriggerRule.cgi
CVSS 5.3
CVE-2024-57679
MEDIUM
D-Link DIR-816 Firmware 1.10CNB05 - Unauthenticated Incorrect Authorization via form2RepeaterSetup.cgi
CVSS 6.5
CVE-2024-57678
MEDIUM
D-Link DIR-816 Firmware - Unauthenticated Incorrect Authorization via form2WlAc.cgi
CVSS 6.5
CVE-2024-57677
MEDIUM
D-Link DIR-816 Firmware 816A2_FWv1.10CNB05_R1B011D88210 - Unauthenticated Incorrect Authorization via form2Wan.cgi
CVSS 6.5
CVE-2024-57676
MEDIUM
D-Link DIR-816 Firmware - Unauthenticated Incorrect Authorization via form2WlanBasicSetup.cgi
CVSS 6.5
CVE-2024-44136
MEDIUM
iPadOS < 17.5 - Incorrect Authorization
CVSS 4.6
CVE-2024-40771
HIGH
macOS Sonoma <14.5, iOS <16.7.8, iPadOS <16.7.8, watchOS <10.5, tvO...
CVSS 7.8
CVE-2024-13302
MEDIUM
Drupal Pages Restriction Access <2.0.3 - Auth Bypass
CVSS 5.3
CVE-2024-13291
HIGH
Drupal Basic HTTP Authentication < 7.x-1.4 - Incorrect Authorization
CVSS 7.3
CVE-2024-13290
MEDIUM
Drupal OhDear Integration <2.0.4 - Info Disclosure
CVSS 5.3
CVE-2024-56114
MEDIUM
Canlineapp Online 1.1 - Incorrect Authorization for Audit Template Creation
CVSS 6.5
CVE-2024-13282
HIGH
Drupal Block permissions 1.0.0-1.1.x - Incorrect Authorization via Forceful Browsing
CVSS 8.8
CVE-2024-13281
CRITICAL
Drupal Monster Menus <9.3.2 - Auth Bypass
CVSS 9.1
CVE-2024-13278
CRITICAL
Drupal Diff <1.8.0 - Info Disclosure
CVSS 9.1
CVE-2024-13277
CRITICAL
Drupal Smart IP Ban <7.X-1.1 - Auth Bypass
CVSS 9.1
CVE-2024-13271
MEDIUM
Drupal Content Entity Clone <1.0.4 - Info Disclosure
CVSS 4.3
CVE-2024-13270
MEDIUM
Drupal Freelinking <4.0.1 - Info Disclosure
CVSS 4.3
CVE-2024-13266
MEDIUM
Drupal Responsive <4.4.4 - Forceful Browsing
CVSS 5.3
CVE-2024-13258
CRITICAL
Drupal REST & JSON API Authentication < 2.0.13 - Incorrect Authorization
CVSS 9.8
CVE-2024-13257
MEDIUM
Drupal Commerce View Receipt <1.0.3 - Info Disclosure
CVSS 5.3
CVE-2024-13253
CRITICAL
Drupal Advanced PWA <1.5.0 - Forceful Browsing
CVSS 9.1
Details
Vulnerabilities
3,070
Exploit Likelihood
High