CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,087 vulnerabilities with CWE-863
CVE-2024-36265 CRITICAL
Apache Submarine Server Core <0.8.0 - Incorrect Authorization
CVSS 9.8
CVE-2024-2698 HIGH
FreeIPA 4.11.0-4.11.2 - Incorrect Authorization in S4U2Proxy Delegation Check
CVSS 8.8
CVE-2024-0160 MEDIUM
Dell Client Platform Firmware - Unauthenticated BIOS Authorization Bypass via Physical Access
CVSS 6.8
CVE-2024-31402 MEDIUM
Cybozu Garoon 5.0.0-5.15.2 - Authenticated Incorrect Authorization in Shared To-Dos
CVSS 4.3
CVE-2024-31403 MEDIUM
Cybozu Garoon 5.0.0-6.0.0 - Authenticated Incorrect Authorization in Memo Data Handling
CVSS 5.4
CVE-2024-2473 MEDIUM
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
CVSS 5.3
CVE-2024-27848 HIGH
macOS Sonoma <14.5 - Privilege Escalation
CVSS 7.8
CVE-2024-4146 CRITICAL
lunary < 1.2.26 - Incorrect Authorization in checkProjectAccess Method
CVSS 9.8
CVE-2024-3404 MEDIUM
gaizhenbiao/chuanhuchatgpt < 20240919-4 - Authenticated Incorrect Authorization via History Path Access
CVSS 6.5
CVE-2024-37154 MEDIUM
evmos - Improper Authorization in ClawbackVestingAccount
CVSS 5.3
CVE-2024-3504 MEDIUM
lunary-ai/lunary <1.2.7 - Privilege Escalation
CVSS 6.5
CVE-2024-3033 CRITICAL
AnythingLLM < 1.0.0 - Unauthenticated Destructive VectorDB Actions via /api/v/ Endpoint
CVSS 9.4
CVE-2024-5324 HIGH
WordPress Login/Signup Popup <2.7.2 - Info Disclosure
CVSS 8.8
CVE-2024-23669 MEDIUM
FortiWebManager 6.2.3-6.2.4, 6.3.0, 7.0.0-7.0.4, 7.2.0 - Unauthenticated Remote Code Execution via HTTP Requests or CLI
CVSS 6.5
CVE-2024-31682 CRITICAL
Phone Cleaner: Boost & Clean <2.2.0 - Auth Bypass
CVSS 9.8
CVE-2024-32983 HIGH
Misskey < 2024.5.0 - Activity Spoofing via Improper JSON Normalization
CVSS 8.2
CVE-2024-36963 HIGH
Linux Kernel - Incorrect Authorization in tracefs Remount Permission Handling
CVSS 7.8
CVE-2024-35353 CRITICAL
Dio Physics School Assistant 2.3 - Incorrect Authorization via Users.php ID Parameter
CVSS 9.8
CVE-2024-36377 MEDIUM
JetBrains TeamCity <2024.03.2 - Privilege Escalation
CVSS 6.5
CVE-2024-36376 MEDIUM
JetBrains TeamCity <2024.03.2 - Privilege Escalation
CVSS 6.5
CVE-2024-36365 MEDIUM
JetBrains TeamCity <2022.04.7,2022.10.6,2023.05.6,2023.11.5,2024.03...
CVSS 6.8
CVE-2024-36364 MEDIUM
JetBrains TeamCity <2022.04.7,2022.10.6,2023.05.6,2023.11.5 - Info ...
CVSS 6.5
CVE-2024-36037 MEDIUM
Zoho ManageEngine ADAudit Plus <7260 - Info Disclosure
CVSS 5.5
CVE-2024-36055 MEDIUM
Marvin Test HW.exe < 5.0.5.0 - Unauthenticated Denial of Service via MmMapIoSpace API
CVSS 5.5
CVE-2024-1803 MEDIUM
EmbedPress < 3.9.12 - Authenticated Unauthorized Access via PDF Embed Block
CVSS 4.3
Details
Vulnerabilities 3,087
Exploit Likelihood High