The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,087 vulnerabilities with CWE-863
CVE-2024-39905
MEDIUM
Red-DiscordBot 3.5.0-3.5.9 - Incorrect Authorization via @commands.can_manage_channel()
CVSS 5.3
CVE-2024-6150
MEDIUM
Citrix Provisioning - Unauthenticated Denial of Service via Target VM Availability Disruption
CVSS 4.3
CVE-2024-39871
MEDIUM
SINEMA Remote Connect Server < 3.2 SP1 - Authenticated Privilege Escalation via Device Settings Misconfiguration
CVSS 6.3
CVE-2024-39696
HIGH
evmos < 19.0.0 - Incorrect Authorization via Vesting Account Funder Address
CVSS 8.8
CVE-2024-2231
MEDIUM
2code Himer <= 2.1.1 - Missing Authorization Check
CVSS 6.5
CVE-2024-39324
LOW
ai-admin-graphql 2022.04.1-2022.10.9 - Insufficient Access Control via GraphQL API
CVSS 3.8
CVE-2024-39322
MEDIUM
Aimeos ai-admin-jsonadm < 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, 2024.4.2 - Incorrect Authorization
CVSS 5.5
CVE-2024-39323
HIGH
ai-admin-graphql 2022.04.1-2022.10.9, 2023.04.1-2023.10.5, 2024.04.1-2024.04.5 - Improper Access Control
CVSS 7.1
CVE-2024-37905
HIGH
authentik < 2024.2.4 - Improper Access Control via API-Access-Token Mechanism
CVSS 8.8
CVE-2024-39352
MEDIUM
Synology BC500 and TC500 Firmware < 1.0.7-0298 - Authenticated Firmware Integrity Check Bypass
CVSS 4.9
CVE-2024-6086
MEDIUM
lunary 1.2.7 - Incorrect Authorization in Organization Name Change
CVSS 4.3
CVE-2024-5714
MEDIUM
lunary 1.2.4 - Incorrect Authorization via Project ID Manipulation
CVSS 6.8
CVE-2024-3331
MEDIUM
Spotfire Enterprise Runtime for R - Server Edition 1.12.7-1.20.0 - Incorrect Authorization
CVSS 6.8
CVE-2024-6323
HIGH
GitLab EE <16.11.5, <17.0.3, <17.1.1 - Info Disclosure
CVSS 7.5
CVE-2024-4011
LOW
GitLab CE/EE <16.11.5-17.1.1 - Info Disclosure
CVSS 3.1
CVE-2024-5071
MEDIUM
Bookster < 1.1.0 - Incorrect Authorization via Appointment Status Manipulation
CVSS 6.5
CVE-2024-38369
CRITICAL
XWiki Platform - Privilege Escalation
CVSS 9.9
CVE-2024-1639
MEDIUM
License Manager for WooCommerce <= 3.0.6 - Authenticated Arbitrary License Key Exposure via Missing Capability Check
CVSS 6.5
CVE-2024-4390
MEDIUM
Depicter < 3.0.2 - Authenticated Arbitrary Nonce Generation
CVSS 6.5
CVE-2024-38329
HIGH
IBM Storage Protect for Virtual Environments - Auth Bypass
CVSS 7.7
CVE-2024-5860
MEDIUM
Tickera < 3.5.2.9 - Authenticated Unauthorized Data Deletion via tc_dl_delete_tickets AJAX Action
CVSS 4.3
CVE-2024-34130
MEDIUM
Acrobat Mobile Sign <24.4.2.33155 - Auth Bypass
CVSS 5.5
CVE-2024-34106
MEDIUM
Adobe Commerce <2.4.7 - Auth Bypass
CVSS 5.3
CVE-2024-2098
HIGH
Download Manager <= 3.2.89 - Unauthenticated Password-Protected File Download via protectMediaLibrary Function
CVSS 7.5
CVE-2024-37300
HIGH
oauthenticator < 16.3.1 - Incorrect Authorization via GlobusOAuthenticator Configuration
CVSS 8.1
Details
Vulnerabilities
3,087
Exploit Likelihood
High