CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,070 vulnerabilities with CWE-863
CVE-2024-44287 MEDIUM
macOS < 13.7.1, < 14.7.1, < 15.1 - Unauthorized File System Modification
CVSS 5.5
CVE-2024-44270 HIGH
macOS < 13.7.1, < 14.7.1, < 15.1 - Sandbox Restriction Bypass via Logic Issue
CVSS 8.6
CVE-2024-44253 MEDIUM
macOS < 13.7.1, < 14.7.1, < 15.1 - Unauthorized File System Modification
CVSS 5.5
CVE-2024-44247 MEDIUM
macOS < 13.7.1, < 14.7.1, < 15.1 - Unauthorized File System Modification
CVSS 5.5
CVE-2024-44196 MEDIUM
macOS < 13.7.1, < 14.7.1, < 15.1 - Unauthorized File System Modification
CVSS 5.5
CVE-2024-44137 MEDIUM
macOS < 13.7.1, < 14.7.1, < 15 - Unauthenticated Lock Screen Data Exposure
CVSS 4.6
CVE-2024-40855 MEDIUM
macOS < 13.7.1, < 14.7.1, < 15 and visionOS < 2 - Unprotected User Data Exposure via Sandbox Bypass
CVSS 5.5
CVE-2024-9825 MEDIUM
Chef Habitat <10315/20240913162802 - IDOR
CVSS 5.4
CVE-2024-48936 MEDIUM
Slurm < 24.05.4 - Incorrect Authorization via Step Manager
CVSS 5.0
CVE-2024-48237 CRITICAL
WTCMS 1.0 - Incorrect Access Control in HomebaseController
CVSS 9.8
CVE-2024-49376 HIGH
Autolab <3.0.0 - Privilege Escalation
CVSS 8.8
CVE-2024-47025 MEDIUM
Android - Local Information Disclosure via drm_fw.c ppmp_protect_buf Logic Error
CVSS 5.5
CVE-2024-44099 MEDIUM
Android - Local Information Disclosure via Insecure Default Value
CVSS 5.5
CVE-2024-41617 CRITICAL
Money Manager EX WebApp 1.2.2 - RCE
CVSS 9.8
CVE-2024-45261 HIGH
GL-iNet devices <4.6.2 - Privilege Escalation
CVSS 8.0
CVE-2024-45260 HIGH
GL-iNet <4.6.2 - Privilege Escalation
CVSS 8.0
CVE-2024-10295 HIGH
Red Hat 3scale API Management Platform 2 - Unauthenticated Authentication Bypass via Malformed Basic Auth Header
CVSS 7.5
CVE-2024-48548 CRITICAL
Cloud Smart Lock 2.0.1 - Incorrect Authorization via Device Binding API
CVSS 9.3
CVE-2024-48547 HIGH
DreamCatcher Life <1.8.7 - Info Disclosure
CVSS 8.4
CVE-2024-48546 HIGH
Wear Sync 1.2.0 - Incorrect Authorization in Firmware Update and Download
CVSS 8.4
CVE-2024-48545 HIGH
IVY Smart 4.5.0 - Incorrect Authorization in Firmware Update and Download
CVSS 8.4
CVE-2024-48544 HIGH
Sylvania Smart Home <3.0.3 - Info Disclosure
CVSS 8.4
CVE-2024-48542 HIGH
Yamaha Headphones Controller 1.6.7 - Info Disclosure
CVSS 8.4
CVE-2024-48541 HIGH
Ruochan Smart <4.4.7 - Info Disclosure
CVSS 8.4
CVE-2024-48540 MEDIUM
XIAO HE Smart 4.3.1 - Info Disclosure
CVSS 6.2
Details
Vulnerabilities 3,070
Exploit Likelihood High