CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,087 vulnerabilities with CWE-863
CVE-2024-1738 HIGH
lunary < 1.2.4 - Unauthenticated Incorrect Authorization in Evaluations API Endpoint
CVSS 7.5
CVE-2024-31990 MEDIUM
Argo CD <2.10.7-2.8.16 - Privilege Escalation
CVSS 4.8
CVE-2024-1307 MEDIUM
Smart Forms < 2.6.94 - Incorrect Authorization
CVSS 6.5
CVE-2024-27309 HIGH
Apache Kafka 3.5.0-3.6.1 and kafka-metadata 3.5.0-3.6.2 - Incorrect Authorization during ZooKeeper to KRaft Migration
CVSS 7.4
CVE-2024-3388 MEDIUM
Palo Alto Networks PAN-OS - Privilege Escalation
CVSS 4.1
CVE-2024-1741 CRITICAL
lunary < 1.2.8 - Unauthenticated Improper Authorization via Old Authorization Token
CVSS 9.1
CVE-2024-1740 CRITICAL
lunary < 1.2.7 - Incorrect Authorization via Uninvalidated Authorization Token
CVSS 9.1
CVE-2024-30260 LOW
undici < 5.28.4 - Improper Authorization via Uncleared Headers in undici.request()
CVSS 3.9
CVE-2024-29834 MEDIUM
Apache Kafka - Privilege Escalation
CVSS 6.4
CVE-2024-31134 MEDIUM
JetBrains TeamCity < 2024.03 - Authenticated User Registration Bypass
CVSS 6.5
CVE-2024-29892 MEDIUM
ZITADEL <2.48.3 - Command Injection
CVSS 6.1
CVE-2024-23451 MEDIUM
Elasticsearch 8.10.0-8.12.2 - Incorrect Authorization in Remote Cluster Security API Key Model
CVSS 4.4
CVE-2024-2915 HIGH
Dovolations Server <2024.1.6 - Privilege Escalation
CVSS 8.8
CVE-2024-27933 HIGH
Deno 1.39.0 - Permission Prompt Bypass via File Descriptor Manipulation
CVSS 8.2
CVE-2024-27105 HIGH
Frappe <14.66.3-15.16.0 - Privilege Escalation
CVSS 8.1
CVE-2024-28394 CRITICAL
Advanced Plugins reportsstatistics <1.3.20 - RCE
CVSS 9.8
CVE-2024-22412 LOW
ClickHouse <24.0.2.54535 - Auth Bypass
CVSS 2.4
CVE-2024-2557 MEDIUM
kishor-23 Food Waste Management System 1.0 - Improper Authorization in /admin/admin.php
CVSS 5.3
CVE-2024-23823 MEDIUM
vantage6 < 4.2.1 and >=0 < 4.3.0 - Permissive Cross-domain Security Policy
CVSS 4.2
CVE-2024-1479 MEDIUM
WP Show Posts <1.1.4 - Info Disclosure
CVSS 5.3
CVE-2024-1452 MEDIUM
GenerateBlocks <1.8.2 - Info Disclosure
CVSS 4.3
CVE-2024-28098 MEDIUM
Apache Pulsar 2.7.1-2.10.5 2.11.0-2.11.3 3.0.0-3.0.2 3.1.0-3.1.2 3.2.0 - Authenticated Incorrect Authorization
CVSS 6.4
CVE-2024-22133 MEDIUM
SAP Fiori Front End Server - version 605 - Info Disclosure
CVSS 4.6
CVE-2024-23262 LOW
iPadOS < 16.7.6 and 17.4 - Incorrect Authorization
CVSS 3.3
CVE-2024-23255 LOW
iPadOS < 17.4 and macOS 14.0-14.4 - Unauthenticated Hidden Photos Album Access
CVSS 2.4
Details
Vulnerabilities 3,087
Exploit Likelihood High