CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,087 vulnerabilities with CWE-863
CVE-2024-5258 MEDIUM
GitLab 16.10-16.10.5, 16.11-16.11.2, 17.0 - Authenticated Authorization Bypass via Pipeline Naming Convention
CVSS 4.4
CVE-2024-27312 HIGH
Zohocorp ManageEngine PAM360 6600 - Privilege Escalation
CVSS 8.1
CVE-2024-3745 HIGH
MSI Afterburner v4.6.6.16381 Beta 3 - Privilege Escalation
CVSS 7.8
CVE-2024-34434 MEDIUM
WordPress MDTF <1.3.3.2 - Code Injection
CVSS 6.5
CVE-2024-35187 CRITICAL
Stalwart Mail Server <0.8.0 - Privilege Escalation
CVSS 9.1
CVE-2024-31409 MEDIUM
CyberPower PowerPanel < 4.9.0 - Incorrect Authorization via MQTT Wildcard Access
CVSS 6.5
CVE-2024-3722 MEDIUM
Swift Performance Lite <2.3.6.18 - Auth Bypass
CVSS 5.4
CVE-2024-34701 MEDIUM
MediaWiki Extension - Info Disclosure
CVSS 5.9
CVE-2024-31441 HIGH
DataEase < 1.18.19 - Arbitrary File Read via ClickHouse Data Source Connection Parameters
CVSS 7.5
CVE-2024-27798 HIGH
macOS Sonoma <14.5 - Privilege Escalation
CVSS 7.8
CVE-2024-34346 HIGH
Deno < 1.43.1 - Incorrect Authorization via Privileged File Access
CVSS 8.4
CVE-2024-0043 HIGH
Android - Incorrect Authorization in Notification Listener Grant
CVSS 7.8
CVE-2024-28148 MEDIUM
Apache Superset < 3.1.2 - Authenticated Incorrect Authorization via REST API Request
CVSS 4.3
CVE-2024-3957 MEDIUM
Booster for WooCommerce <= 7.1.8 - Unauthenticated Arbitrary Shortcode Execution
CVSS 6.5
CVE-2024-1677 MEDIUM
Print Labels with Barcodes < 3.4.6 - Authenticated Missing Authorization in AJAX Functions
CVSS 6.3
CVE-2024-34146 MEDIUM
Jenkins Git server Plugin <114.v068a_c7cc2574 - Privilege Escalation
CVSS 6.5
CVE-2024-2378 HIGH
Hitachi Energy SDM600 - Incorrect Authorization in Web-Authentication Component
CVSS 8.0
CVE-2024-4006 MEDIUM
GitLab CE/EE <16.9.6/<16.10.4/<16.11.1 - Info Disclosure
CVSS 4.3
CVE-2024-28627 HIGH
Flipsnack <18/03/2024 - Info Disclosure
CVSS 7.5
CVE-2024-32470 MEDIUM
Tolgee 3.57.2-3.57.4 - Incorrect Authorization via Admin API Key
CVSS 6.5
CVE-2024-31452 HIGH
OpenFGA 1.5.0-1.5.3 - Authorization Bypass via Exclusion or Intersection in Check or ListObjects APIs
CVSS 8.1
CVE-2024-27086 LOW
Microsoft.Identity.Client 4.48.0-4.60.0 - Local Denial of Service via Activity Export Misconfiguration
CVSS 3.9
CVE-2024-21120 MEDIUM
Oracle Outside In Technology 8.5.6 and 8.5.7 - Incorrect Authorization
CVSS 5.3
CVE-2024-21083 HIGH
Oracle BI Publisher 7.0.0.0.0 and 12.2.1.4.0 - Authenticated Remote Code Execution via Script Engine
CVSS 7.2
CVE-2024-21010 CRITICAL
Oracle Hospitality Simphony 19.1.0-19.5.4 - Authenticated Remote Code Execution via HTTP
CVSS 9.9
Details
Vulnerabilities 3,087
Exploit Likelihood High