The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,087 vulnerabilities with CWE-863
CVE-2024-43131
HIGH
WPWeb Docket <1.7.0 - Info Disclosure
CVSS 7.5
CVE-2024-41941
MEDIUM
SINEC NMS < 3.0 - Authenticated Authorization Bypass
CVSS 4.3
CVE-2024-41939
HIGH
SINEC NMS < 3.0 - Authenticated Privilege Escalation via Improper Authorization
CVSS 8.8
CVE-2024-42473
HIGH
OpenFGA 1.5.7-1.5.8 - Authorization Bypass via Check API with 'but not' and 'from' Expressions
CVSS 7.5
CVE-2024-7266
MEDIUM
Naukowa i Akademicka Sie Komputerowa EZD RP 15-15.83 16-16.14 17-17.1 - Authenticated Incorrect User Management
CVSS 4.3
CVE-2024-7265
HIGH
Naukowa i Akademicka Sie Komputerowa EZD RP 15-15.83, 16-16.14, 17-17.1 - Privilege Escalation via Password Change
CVSS 8.8
CVE-2024-42062
HIGH
Apache CloudStack 4.10.0-4.19.1.0 - Authenticated Privilege Escalation via API Key Query
CVSS 7.2
CVE-2024-7004
MEDIUM
Google Chrome < 127.0.6533.72 - Discretionary Access Control Bypass via Safe Browsing Input Validation
CVSS 4.3
CVE-2024-6358
MEDIUM
OpenText ArcSight Intelligence - Auth Bypass
CVSS 6.3
CVE-2024-6202
CRITICAL
HaloITSM < 2.143.61 - Unauthenticated SAML XML Signature Wrapping
CVSS 9.8
CVE-2024-6782
CRITICAL
Calibre 6.9.0-7.14.0 - Unauthenticated RCE
CVSS 9.8
CVE-2024-40530
HIGH
Pantera CRM 401.152 and 402.072 - Unauthenticated Authorization Bypass via X-Forwarded-For Header
CVSS 7.5
CVE-2024-38856
CRITICAL
KEV
Apache OFBiz forgotPassword/ProgramExport RCE
CVSS 9.8
CVE-2024-38884
HIGH
Caterease 16.0.1.1663-24.0.1.2405 - Authentication Bypass via Improper Security Checks
CVSS 7.8
CVE-2024-6695
CRITICAL
Cozmoslabs Profile Builder <= 3.11.9 - Privilege Escalation
CVSS 9.8
CVE-2024-41670
HIGH
PrestaShop <6.4.2, <3.18.1 - Info Disclosure
CVSS 7.5
CVE-2024-7062
HIGH
Nimble Commander < 1.6.1 - Privilege Escalation via Files.PrivilegedIOHelperV2
CVSS 8.8
CVE-2024-4447
CRITICAL
dotCMS core 4.2.1-23.01.20 - Authenticated Information Disclosure and Privilege Escalation via DWR Endpoints
CVSS 9.9
CVE-2024-4811
LOW
Octopus Server 2023.1.4189-2023.4.8608 - Incorrect Authorization
CVSS 2.2
CVE-2024-36536
CRITICAL
Fabedge v0.8.1 - Privilege Escalation
CVSS 9.8
CVE-2024-41110
CRITICAL
Docker 19.03.0-27.1.0 - Authorization Bypass via API Request Body Omission
CVSS 9.9
CVE-2024-31970
HIGH
AdTran SRG 834-5 HDC17600021F1 - Privilege Escalation
CVSS 8.8
CVE-2024-21149
HIGH
Oracle Enterprise Asset Management 12.2.11-12.2.13 - Incorrect Authorization in Work Definition Issues
CVSS 8.1
CVE-2024-5817
MEDIUM
GitHub Enterprise Server < 3.14 - Incorrect Authorization via GitHub Projects
CVSS 6.5
CVE-2024-5816
MEDIUM
GitHub Enterprise Server < 3.14 - Incorrect Authorization via Scoped User Access Token
CVSS 5.3
Details
Vulnerabilities
3,087
Exploit Likelihood
High