CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,070 vulnerabilities with CWE-863
CVE-2024-45204 MEDIUM
Veeam Backup & Replication 12.0.0.1402-12.3.0.310 - Incorrect Authorization Leading to NTLM Hash Exposure
CVSS 4.3
CVE-2024-42452 HIGH
Veeam Backup & Replication - Privilege Escalation
CVSS 8.8
CVE-2024-42451 MEDIUM
Veeam Backup & Replication - Info Disclosure
CVSS 6.5
CVE-2024-45106 HIGH
Apache Ozone 1.4.0 - Authenticated S3 Secret Manipulation via HTTP Endpoint
CVSS 8.1
CVE-2024-53937 HIGH
Victure RX1800 WiFi 6 Router EN_V1.0.0_r12_110933 - RCE
CVSS 8.8
CVE-2024-53941 HIGH
Victure RX1800 WiFi 6 Router EN_1.0.0_r12_110933 - Info Disclosure
CVSS 8.8
CVE-2024-52732 CRITICAL
wms-Warehouse management system-zeqp <2.20.9.1 - Info Disclosure
CVSS 9.1
CVE-2024-36611 HIGH
symfony/security-http < 7.1.0 - Incorrect Authorization via Empty Username or Password
CVSS 7.5
CVE-2024-48651 HIGH
ProFTPD < 1.3.8b - Privilege Escalation via mod_sql
CVSS 7.5
CVE-2024-54124 HIGH
Click Studios Passwordstate <build 9920 - Privilege Escalation
CVSS 8.8
CVE-2024-11669 MEDIUM
GitLab CE/EE <17.4.5-17.6.1 - Info Disclosure
CVSS 6.5
CVE-2024-50671 MEDIUM
Adapt Learning Adapt Authoring Tool <= 0.11.3 - Info Disclosure
CVSS 4.3
CVE-2024-7915 HIGH
Sensei Mac Cleaner - Privilege Escalation
CVSS 7.8
CVE-2024-11672 MEDIUM
Drevolutions Remote Desktop Manager <2024.2.21 - Auth Bypass
CVSS 4.3
CVE-2024-11670 MEDIUM
Drevolutions Remote Desktop Manager <2024.2.21 - Auth Bypass
CVSS 5.4
CVE-2024-11176 MEDIUM
M-Files Aino <24.10 - Info Disclosure
CVE-2024-21287 HIGH KEV
Oracle Agile PLM Framework 9.3.6 - Unauthenticated Incorrect Authorization in Software Development Kit
CVSS 7.5
CVE-2024-52584 MEDIUM
Autolab 3.0.1 - Incorrect Authorization via Submission ID Endpoint
CVSS 5.4
CVE-2024-48901 MEDIUM
Moodle < 4.1.14 - Improper Authorization in Report Schedule Access
CVSS 4.3
CVE-2024-48897 MEDIUM
Moodle < 4.1.14 - Improper Authorization in RSS Feed Management
CVSS 4.3
CVE-2024-52518 MEDIUM
Nextcloud Server 28.0.0-28.0.11 - Authenticated External Storage Manipulation
CVSS 4.4
CVE-2024-50650 HIGH
python_book 1.0 - Incorrect Authorization via ID Parameter
CVSS 7.5
CVE-2024-50647 HIGH
python_food 1.0 - Unauthenticated Sensitive Information Exposure via User Info API
CVSS 7.5
CVE-2024-31695 CRITICAL
Binance: BTC, Crypto and NFTS <v2.85.4 - Auth Bypass
CVSS 9.8
CVE-2024-3379 HIGH
lunary-ai/lunary <1.2.7 - Info Disclosure
CVSS 8.1
Details
Vulnerabilities 3,070
Exploit Likelihood High