The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,087 vulnerabilities with CWE-863
CVE-2024-23250
MEDIUM
iPadOS < 17.4 - Unauthorized Bluetooth Microphone Access
CVSS 5.5
CVE-2024-28229
MEDIUM
JetBrains YouTrack < 2024.1.25893 - Incorrect Authorization
CVSS 6.5
CVE-2024-0199
HIGH
GitLab 11.3-16.7.6 16.8.3-16.8.3 - Incorrect Authorization Bypass via Crafted Payload in Old Feature Branch
CVSS 7.7
CVE-2024-27915
MEDIUM
Sulu 2.2.0-2.4.16 and 2.5.0-2.5.12 - Incorrect Authorization in Webspace Security System
CVSS 6.8
CVE-2024-27288
MEDIUM
1Panel < 1.10.1-lts - Unauthenticated Incorrect Authorization
CVSS 6.3
CVE-2024-24761
HIGH
Galette 1.0.0-1.0.1 - Incorrect Authorization
CVSS 7.5
CVE-2024-28174
MEDIUM
JetBrains TeamCity < 2023.11.4 - Incorrect Authorization in S3 Artifact Storage Plugin
CVSS 5.8
CVE-2024-27139
HIGH
Apache Archiva <2.0.0 - Unauthorized Access
CVSS 7.5
CVE-2024-27138
HIGH
Apache Archiva - Incorrect Authorization via User Registration Bypass
CVSS 7.5
CVE-2024-20291
MEDIUM
Cisco NX-OS - Unauthenticated Access Control Bypass via Port Channel Subinterface ACL Programming
CVSS 5.8
CVE-2024-25170
CRITICAL
Mezzanine 6.0.0 - Incorrect Authorization via Host Header Manipulation
CVSS 9.1
CVE-2024-26016
MEDIUM
Apache Superset < 3.0.4, 3.1.0 - Authenticated Dashboard Ownership Takeover via Import
CVSS 4.3
CVE-2024-24779
MEDIUM
Apache Superset <3.0.4, >3.1.0-<3.1.1 - Info Disclosure
CVSS 5.0
CVE-2024-24773
MEDIUM
Apache Superset <3.0.4, >3.1.0-<3.1.1 - SQL Injection
CVSS 4.9
CVE-2024-26145
MEDIUM
Discourse Calendar < 2024-02-21 - Incorrect Authorization via Attendance Update Request
CVSS 6.5
CVE-2024-1156
HIGH
Emerson Data Record AD < 2.0.1 - Authenticated Privilege Escalation via RabbitMQ Configuration
CVSS 7.8
CVE-2024-1155
HIGH
SystemLink Elixir - Privilege Escalation
CVSS 7.8
CVE-2024-25604
MEDIUM
Liferay Portal <7.4.3.4 - Privilege Escalation
CVSS 6.5
CVE-2024-25149
MEDIUM
Liferay Digital Experience Platform 7.2.0-7.4.1 - Authenticated Incorrect Authorization via Child Site Membership
CVSS 5.4
CVE-2024-21987
MEDIUM
SnapCenter <5.0 - Privilege Escalation
CVSS 5.4
CVE-2024-0017
MEDIUM
Android - Local Information Disclosure via CameraActivity Permissions Bypass
CVSS 5.5
CVE-2024-1482
HIGH
GitHub Enterprise Server 3.8.0-3.11.9 - Authenticated Arbitrary GitHub Actions Workflow Execution via Branch Creation
CVSS 7.1
CVE-2024-24966
MEDIUM
F5OS-A and F5OS-C - Incorrect Authorization via LDAP Remote Authentication
CVSS 6.2
CVE-2024-24751
MEDIUM
sf_event_mgt 7.0.0-7.3.9 - Improper Access Control in Backend Module
CVSS 4.3
CVE-2024-23833
HIGH
OpenRefine < 3.7.8 - Path Traversal via JDBC Query
CVSS 7.5
Details
Vulnerabilities
3,087
Exploit Likelihood
High