The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,070 vulnerabilities with CWE-863
CVE-2024-44287
MEDIUM
macOS < 13.7.1, < 14.7.1, < 15.1 - Unauthorized File System Modification
CVSS 5.5
CVE-2024-44270
HIGH
macOS < 13.7.1, < 14.7.1, < 15.1 - Sandbox Restriction Bypass via Logic Issue
CVSS 8.6
CVE-2024-44253
MEDIUM
macOS < 13.7.1, < 14.7.1, < 15.1 - Unauthorized File System Modification
CVSS 5.5
CVE-2024-44247
MEDIUM
macOS < 13.7.1, < 14.7.1, < 15.1 - Unauthorized File System Modification
CVSS 5.5
CVE-2024-44196
MEDIUM
macOS < 13.7.1, < 14.7.1, < 15.1 - Unauthorized File System Modification
CVSS 5.5
CVE-2024-44137
MEDIUM
macOS < 13.7.1, < 14.7.1, < 15 - Unauthenticated Lock Screen Data Exposure
CVSS 4.6
CVE-2024-40855
MEDIUM
macOS < 13.7.1, < 14.7.1, < 15 and visionOS < 2 - Unprotected User Data Exposure via Sandbox Bypass
CVSS 5.5
CVE-2024-9825
MEDIUM
Chef Habitat <10315/20240913162802 - IDOR
CVSS 5.4
CVE-2024-48936
MEDIUM
Slurm < 24.05.4 - Incorrect Authorization via Step Manager
CVSS 5.0
CVE-2024-48237
CRITICAL
WTCMS 1.0 - Incorrect Access Control in HomebaseController
CVSS 9.8
CVE-2024-49376
HIGH
Autolab <3.0.0 - Privilege Escalation
CVSS 8.8
CVE-2024-47025
MEDIUM
Android - Local Information Disclosure via drm_fw.c ppmp_protect_buf Logic Error
CVSS 5.5
CVE-2024-44099
MEDIUM
Android - Local Information Disclosure via Insecure Default Value
CVSS 5.5
CVE-2024-41617
CRITICAL
Money Manager EX WebApp 1.2.2 - RCE
CVSS 9.8
CVE-2024-45261
HIGH
GL-iNet devices <4.6.2 - Privilege Escalation
CVSS 8.0
CVE-2024-45260
HIGH
GL-iNet <4.6.2 - Privilege Escalation
CVSS 8.0
CVE-2024-10295
HIGH
Red Hat 3scale API Management Platform 2 - Unauthenticated Authentication Bypass via Malformed Basic Auth Header
CVSS 7.5
CVE-2024-48548
CRITICAL
Cloud Smart Lock 2.0.1 - Incorrect Authorization via Device Binding API
CVSS 9.3
CVE-2024-48547
HIGH
DreamCatcher Life <1.8.7 - Info Disclosure
CVSS 8.4
CVE-2024-48546
HIGH
Wear Sync 1.2.0 - Incorrect Authorization in Firmware Update and Download
CVSS 8.4
CVE-2024-48545
HIGH
IVY Smart 4.5.0 - Incorrect Authorization in Firmware Update and Download
CVSS 8.4
CVE-2024-48544
HIGH
Sylvania Smart Home <3.0.3 - Info Disclosure
CVSS 8.4
CVE-2024-48542
HIGH
Yamaha Headphones Controller 1.6.7 - Info Disclosure
CVSS 8.4
CVE-2024-48541
HIGH
Ruochan Smart <4.4.7 - Info Disclosure
CVSS 8.4
CVE-2024-48540
MEDIUM
XIAO HE Smart 4.3.1 - Info Disclosure
CVSS 6.2
Details
Vulnerabilities
3,070
Exploit Likelihood
High