The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,087 vulnerabilities with CWE-863
CVE-2024-5258
MEDIUM
GitLab 16.10-16.10.5, 16.11-16.11.2, 17.0 - Authenticated Authorization Bypass via Pipeline Naming Convention
CVSS 4.4
CVE-2024-27312
HIGH
Zohocorp ManageEngine PAM360 6600 - Privilege Escalation
CVSS 8.1
CVE-2024-3745
HIGH
MSI Afterburner v4.6.6.16381 Beta 3 - Privilege Escalation
CVSS 7.8
CVE-2024-34434
MEDIUM
WordPress MDTF <1.3.3.2 - Code Injection
CVSS 6.5
CVE-2024-35187
CRITICAL
Stalwart Mail Server <0.8.0 - Privilege Escalation
CVSS 9.1
CVE-2024-31409
MEDIUM
CyberPower PowerPanel < 4.9.0 - Incorrect Authorization via MQTT Wildcard Access
CVSS 6.5
CVE-2024-3722
MEDIUM
Swift Performance Lite <2.3.6.18 - Auth Bypass
CVSS 5.4
CVE-2024-34701
MEDIUM
MediaWiki Extension - Info Disclosure
CVSS 5.9
CVE-2024-31441
HIGH
DataEase < 1.18.19 - Arbitrary File Read via ClickHouse Data Source Connection Parameters
CVSS 7.5
CVE-2024-27798
HIGH
macOS Sonoma <14.5 - Privilege Escalation
CVSS 7.8
CVE-2024-34346
HIGH
Deno < 1.43.1 - Incorrect Authorization via Privileged File Access
CVSS 8.4
CVE-2024-0043
HIGH
Android - Incorrect Authorization in Notification Listener Grant
CVSS 7.8
CVE-2024-28148
MEDIUM
Apache Superset < 3.1.2 - Authenticated Incorrect Authorization via REST API Request
CVSS 4.3
CVE-2024-3957
MEDIUM
Booster for WooCommerce <= 7.1.8 - Unauthenticated Arbitrary Shortcode Execution
CVSS 6.5
CVE-2024-1677
MEDIUM
Print Labels with Barcodes < 3.4.6 - Authenticated Missing Authorization in AJAX Functions
CVSS 6.3
CVE-2024-34146
MEDIUM
Jenkins Git server Plugin <114.v068a_c7cc2574 - Privilege Escalation
CVSS 6.5
CVE-2024-2378
HIGH
Hitachi Energy SDM600 - Incorrect Authorization in Web-Authentication Component
CVSS 8.0
CVE-2024-4006
MEDIUM
GitLab CE/EE <16.9.6/<16.10.4/<16.11.1 - Info Disclosure
CVSS 4.3
CVE-2024-28627
HIGH
Flipsnack <18/03/2024 - Info Disclosure
CVSS 7.5
CVE-2024-32470
MEDIUM
Tolgee 3.57.2-3.57.4 - Incorrect Authorization via Admin API Key
CVSS 6.5
CVE-2024-31452
HIGH
OpenFGA 1.5.0-1.5.3 - Authorization Bypass via Exclusion or Intersection in Check or ListObjects APIs
CVSS 8.1
CVE-2024-27086
LOW
Microsoft.Identity.Client 4.48.0-4.60.0 - Local Denial of Service via Activity Export Misconfiguration
CVSS 3.9
CVE-2024-21120
MEDIUM
Oracle Outside In Technology 8.5.6 and 8.5.7 - Incorrect Authorization
CVSS 5.3
CVE-2024-21083
HIGH
Oracle BI Publisher 7.0.0.0.0 and 12.2.1.4.0 - Authenticated Remote Code Execution via Script Engine
CVSS 7.2
CVE-2024-21010
CRITICAL
Oracle Hospitality Simphony 19.1.0-19.5.4 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
Details
Vulnerabilities
3,087
Exploit Likelihood
High