The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,087 vulnerabilities with CWE-863
CVE-2023-52111
HIGH
Huawei EMUI and HarmonyOS - Improper Authentication in BootLoader Module
CVSS 7.5
CVE-2023-5356
HIGH
GitLab 8.13-16.5.5, 16.6-16.6.3, 16.7-16.7.1 - Incorrect Authorization via Slack/Mattermost Integration
CVSS 7.3
CVE-2023-4812
HIGH
GitLab EE <16.5.6-16.7.2 - Auth Bypass
CVSS 7.6
CVE-2023-41994
MEDIUM
macOS < 14.0 - Unauthorized Camera Access via Extension Permission Bypass
CVSS 5.5
CVE-2023-46906
MEDIUM
juzaweb/cms < 3.4 - Incorrect Access Control via Timezone Field
CVSS 4.9
CVE-2023-41779
MEDIUM
ZTE ZXCLOUD iRAI < 7.23.32 - Authenticated Denial of Service via Illegal Memory Access
CVSS 4.4
CVE-2023-52077
HIGH
Nexkey <12.23Q4.5 - Privilege Escalation
CVSS 8.9
CVE-2023-5644
HIGH
WP Mail Log < 1.1.3 - Incorrect Authorization via REST API Endpoints
CVSS 7.6
CVE-2023-49949
HIGH
Passwork < 6.2.0 - Authenticated 2FA Bypass via Brute-Force Attack
CVSS 8.1
CVE-2023-51649
LOW
Nautobot 1.5.14-1.6.8 - Incorrect Authorization via Job Button Submission
CVSS 3.5
CVE-2023-51380
LOW
GitHub Enterprise Server <3.7.19-3.11.1 - Auth Bypass
CVSS 2.7
CVE-2023-51379
MEDIUM
GitHub Enterprise Server <3.17.19-3.11.1 - Auth Bypass
CVSS 4.9
CVE-2023-50732
HIGH
XWiki 8.3-14.10.6 - Unauthenticated Velocity Script Execution via Document Tree
CVSS 8.3
CVE-2023-7047
MEDIUM
Devolutions Remote Desktop Manager < 2023.3.31.0 - Incorrect Authorization via Remote Tools Context Menu
CVSS 4.4
CVE-2023-50705
MEDIUM
Efacec UC 500e Firmware - Information Disclosure
CVSS 5.3
CVE-2023-49734
HIGH
Apache Superset < 2.1.2, 3.0.0-3.0.1 - Authenticated Incorrect Authorization via Dashboard Chart Ownership
CVSS 7.7
CVE-2023-6355
MEDIUM
Gallagher Controller 7000 <9.00.231204b - Privilege Escalation
CVSS 6.8
CVE-2023-41314
HIGH
Apache Doris < 2.0.3 - Unauthenticated Arbitrary File Read and Denial of Service via Snapshot and Log File API
CVSS 8.2
CVE-2023-3511
LOW
GitLab EE <16.4.4-16.6.2 - Info Disclosure
CVSS 2.0
CVE-2023-6837
HIGH
WSO2 API Manager 2.5.0-2.5.0.31 - User Impersonation via JIT Provisioning
CVSS 8.5
CVE-2023-45185
HIGH
IBM i Access Client Solutions 1.1.2-1.1.4 and 1.1.4.3-1.1.9.3 - Remote Code Execution via Improper Authority Checks
CVSS 7.4
CVE-2023-50777
MEDIUM
Jenkins PaaSLane Estimate Plugin <= 1.0.4 - Cleartext Storage of Sensitive Information
CVSS 4.3
CVE-2023-47320
HIGH
Silverpeas Core < 6.3.2 - Authenticated Denial of Service via Maintenance Mode Function
CVSS 8.1
CVE-2023-49273
MEDIUM
Umbraco <8.0.0-8.18.10-10.8.1-12.3.4 - Info Disclosure
CVSS 5.4
CVE-2023-48227
MEDIUM
Umbraco CMS 8.0.0-8.18.9 - Incorrect Authorization
CVSS 4.3
Details
Vulnerabilities
3,087
Exploit Likelihood
High