The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,087 vulnerabilities with CWE-863
CVE-2024-36265
CRITICAL
Apache Submarine Server Core <0.8.0 - Incorrect Authorization
CVSS 9.8
CVE-2024-2698
HIGH
FreeIPA 4.11.0-4.11.2 - Incorrect Authorization in S4U2Proxy Delegation Check
CVSS 8.8
CVE-2024-0160
MEDIUM
Dell Client Platform Firmware - Unauthenticated BIOS Authorization Bypass via Physical Access
CVSS 6.8
CVE-2024-31402
MEDIUM
Cybozu Garoon 5.0.0-5.15.2 - Authenticated Incorrect Authorization in Shared To-Dos
CVSS 4.3
CVE-2024-31403
MEDIUM
Cybozu Garoon 5.0.0-6.0.0 - Authenticated Incorrect Authorization in Memo Data Handling
CVSS 5.4
CVE-2024-2473
MEDIUM
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
CVSS 5.3
CVE-2024-27848
HIGH
macOS Sonoma <14.5 - Privilege Escalation
CVSS 7.8
CVE-2024-4146
CRITICAL
lunary < 1.2.26 - Incorrect Authorization in checkProjectAccess Method
CVSS 9.8
CVE-2024-3404
MEDIUM
gaizhenbiao/chuanhuchatgpt < 20240919-4 - Authenticated Incorrect Authorization via History Path Access
CVSS 6.5
CVE-2024-37154
MEDIUM
evmos - Improper Authorization in ClawbackVestingAccount
CVSS 5.3
CVE-2024-3504
MEDIUM
lunary-ai/lunary <1.2.7 - Privilege Escalation
CVSS 6.5
CVE-2024-3033
CRITICAL
AnythingLLM < 1.0.0 - Unauthenticated Destructive VectorDB Actions via /api/v/ Endpoint
CVSS 9.4
CVE-2024-5324
HIGH
WordPress Login/Signup Popup <2.7.2 - Info Disclosure
CVSS 8.8
CVE-2024-23669
MEDIUM
FortiWebManager 6.2.3-6.2.4, 6.3.0, 7.0.0-7.0.4, 7.2.0 - Unauthenticated Remote Code Execution via HTTP Requests or CLI
CVSS 6.5
CVE-2024-31682
CRITICAL
Phone Cleaner: Boost & Clean <2.2.0 - Auth Bypass
CVSS 9.8
CVE-2024-32983
HIGH
Misskey < 2024.5.0 - Activity Spoofing via Improper JSON Normalization
CVSS 8.2
CVE-2024-36963
HIGH
Linux Kernel - Incorrect Authorization in tracefs Remount Permission Handling
CVSS 7.8
CVE-2024-35353
CRITICAL
Dio Physics School Assistant 2.3 - Incorrect Authorization via Users.php ID Parameter
CVSS 9.8
CVE-2024-36377
MEDIUM
JetBrains TeamCity <2024.03.2 - Privilege Escalation
CVSS 6.5
CVE-2024-36376
MEDIUM
JetBrains TeamCity <2024.03.2 - Privilege Escalation
CVSS 6.5
CVE-2024-36365
MEDIUM
JetBrains TeamCity <2022.04.7,2022.10.6,2023.05.6,2023.11.5,2024.03...
CVSS 6.8
CVE-2024-36364
MEDIUM
JetBrains TeamCity <2022.04.7,2022.10.6,2023.05.6,2023.11.5 - Info ...
CVSS 6.5
CVE-2024-36037
MEDIUM
Zoho ManageEngine ADAudit Plus <7260 - Info Disclosure
CVSS 5.5
CVE-2024-36055
MEDIUM
Marvin Test HW.exe < 5.0.5.0 - Unauthenticated Denial of Service via MmMapIoSpace API
CVSS 5.5
CVE-2024-1803
MEDIUM
EmbedPress < 3.9.12 - Authenticated Unauthorized Access via PDF Embed Block
CVSS 4.3
Details
Vulnerabilities
3,087
Exploit Likelihood
High