The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,076 vulnerabilities with CWE-863
CVE-2024-44162
HIGH
Xcode < 16.0 - Unauthorized Keychain Access
CVSS 7.8
CVE-2024-40843
MEDIUM
macOS Sequoia <15 - Info Disclosure
CVSS 5.5
CVE-2024-40770
HIGH
macOS Sequoia <15 - Privilege Escalation
CVSS 7.5
CVE-2024-46918
MEDIUM
MISP < 2.4.198 - Incorrect Authorization in UserLoginProfilesController
CVSS 4.9
CVE-2024-2743
MEDIUM
GitLab 13.3-17.1.6, 17.2-17.2.4, 17.3-17.3.1 - Incorrect Authorization in On-Demand DAST Scan
CVSS 5.3
CVE-2024-8691
HIGH
Palo Alto Networks PAN-OS - Privilege Escalation
CVSS 7.1
CVE-2024-4465
MEDIUM
Guardian/CMC - Privilege Escalation
CVSS 6.0
CVE-2024-44667
HIGH
Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7...
CVSS 8.0
CVE-2024-42423
MEDIUM
Citrix Workspace App <23.9.0.24.4 - Auth Bypass
CVSS 6.1
CVE-2024-6979
MEDIUM
AXIS OS 2024 11.11.0-11.11.94 - Incorrect Authorization
CVSS 6.8
CVE-2024-44114
LOW
SAP NetWeaver Application Server ABAP - Unauthorized Data Exposure via High Privilege Program Execution
CVSS 2.0
CVE-2024-8601
MEDIUM
TechExcel Back Office Software <1.0.0 - Info Disclosure
CVSS 6.5
CVE-2024-34652
MEDIUM
Samsung Android - Incorrect Authorization in kperfmon
CVSS 4.0
CVE-2024-34651
MEDIUM
Samsung Android My Files - Incorrect Authorization
CVSS 6.2
CVE-2024-34650
MEDIUM
Samsung Android - Incorrect Authorization in CocktailbarService
CVSS 4.0
CVE-2024-34642
MEDIUM
Samsung Android One UI Home - Incorrect Authorization
CVSS 4.6
CVE-2024-45588
HIGH
Symphony XTS Web Trading Platform 2.0.0.1_P160 - Authenticated Incorrect Authorization in Preference Module API
CVSS 8.1
CVE-2024-45587
HIGH
Symphony XTS Web Trading Platform 2.0.0.1_P160 - Authenticated Incorrect Authorization in Transaction Module API
CVSS 8.8
CVE-2024-45586
HIGH
Symphony XTS Web/Mobile Trading 2.0.0.1_P160 - Account Takeover via API Parameter Manipulation
CVSS 8.8
CVE-2024-45509
MEDIUM
MISP < 2.4.197 - Improper Access Control in BookmarksController
CVSS 6.5
CVE-2024-38868
HIGH
ManageEngine Endpoint Central < 11.3.2400.15 - Incorrect Authorization during Device Isolation
CVSS 7.6
CVE-2024-41964
HIGH
Kirby < 3.6.6.6 - Incorrect Authorization in Language Management
CVSS 8.1
CVE-2024-43954
MEDIUM
Themeum Droip <= 1.1.1 - Incorrect Authorization
CVSS 6.3
CVE-2024-45043
MEDIUM
OpenTelemetry Collector - Unauthenticated RCE
CVSS 5.3
CVE-2024-45037
MEDIUM
AWS Cloud Development Kit 2.142.0-2.148.0 - Incorrect Authorization via RestApi Construct with CognitoUserPoolAuthorizer
CVSS 6.4
Details
Vulnerabilities
3,076
Exploit Likelihood
High