The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,070 vulnerabilities with CWE-863
CVE-2024-45204
MEDIUM
Veeam Backup & Replication 12.0.0.1402-12.3.0.310 - Incorrect Authorization Leading to NTLM Hash Exposure
CVSS 4.3
CVE-2024-42452
HIGH
Veeam Backup & Replication - Privilege Escalation
CVSS 8.8
CVE-2024-42451
MEDIUM
Veeam Backup & Replication - Info Disclosure
CVSS 6.5
CVE-2024-45106
HIGH
Apache Ozone 1.4.0 - Authenticated S3 Secret Manipulation via HTTP Endpoint
CVSS 8.1
CVE-2024-53937
HIGH
Victure RX1800 WiFi 6 Router EN_V1.0.0_r12_110933 - RCE
CVSS 8.8
CVE-2024-53941
HIGH
Victure RX1800 WiFi 6 Router EN_1.0.0_r12_110933 - Info Disclosure
CVSS 8.8
CVE-2024-52732
CRITICAL
wms-Warehouse management system-zeqp <2.20.9.1 - Info Disclosure
CVSS 9.1
CVE-2024-36611
HIGH
symfony/security-http < 7.1.0 - Incorrect Authorization via Empty Username or Password
CVSS 7.5
CVE-2024-48651
HIGH
ProFTPD < 1.3.8b - Privilege Escalation via mod_sql
CVSS 7.5
CVE-2024-54124
HIGH
Click Studios Passwordstate <build 9920 - Privilege Escalation
CVSS 8.8
CVE-2024-11669
MEDIUM
GitLab CE/EE <17.4.5-17.6.1 - Info Disclosure
CVSS 6.5
CVE-2024-50671
MEDIUM
Adapt Learning Adapt Authoring Tool <= 0.11.3 - Info Disclosure
CVSS 4.3
CVE-2024-7915
HIGH
Sensei Mac Cleaner - Privilege Escalation
CVSS 7.8
CVE-2024-11672
MEDIUM
Drevolutions Remote Desktop Manager <2024.2.21 - Auth Bypass
CVSS 4.3
CVE-2024-11670
MEDIUM
Drevolutions Remote Desktop Manager <2024.2.21 - Auth Bypass
CVSS 5.4
CVE-2024-11176
MEDIUM
M-Files Aino <24.10 - Info Disclosure
CVE-2024-21287
HIGH
KEV
Oracle Agile PLM Framework 9.3.6 - Unauthenticated Incorrect Authorization in Software Development Kit
CVSS 7.5
CVE-2024-52584
MEDIUM
Autolab 3.0.1 - Incorrect Authorization via Submission ID Endpoint
CVSS 5.4
CVE-2024-48901
MEDIUM
Moodle < 4.1.14 - Improper Authorization in Report Schedule Access
CVSS 4.3
CVE-2024-48897
MEDIUM
Moodle < 4.1.14 - Improper Authorization in RSS Feed Management
CVSS 4.3
CVE-2024-52518
MEDIUM
Nextcloud Server 28.0.0-28.0.11 - Authenticated External Storage Manipulation
CVSS 4.4
CVE-2024-50650
HIGH
python_book 1.0 - Incorrect Authorization via ID Parameter
CVSS 7.5
CVE-2024-50647
HIGH
python_food 1.0 - Unauthenticated Sensitive Information Exposure via User Info API
CVSS 7.5
CVE-2024-31695
CRITICAL
Binance: BTC, Crypto and NFTS <v2.85.4 - Auth Bypass
CVSS 9.8
CVE-2024-3379
HIGH
lunary-ai/lunary <1.2.7 - Info Disclosure
CVSS 8.1
Details
Vulnerabilities
3,070
Exploit Likelihood
High