CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,087 vulnerabilities with CWE-863
CVE-2023-52111 HIGH
Huawei EMUI and HarmonyOS - Improper Authentication in BootLoader Module
CVSS 7.5
CVE-2023-5356 HIGH
GitLab 8.13-16.5.5, 16.6-16.6.3, 16.7-16.7.1 - Incorrect Authorization via Slack/Mattermost Integration
CVSS 7.3
CVE-2023-4812 HIGH
GitLab EE <16.5.6-16.7.2 - Auth Bypass
CVSS 7.6
CVE-2023-41994 MEDIUM
macOS < 14.0 - Unauthorized Camera Access via Extension Permission Bypass
CVSS 5.5
CVE-2023-46906 MEDIUM
juzaweb/cms < 3.4 - Incorrect Access Control via Timezone Field
CVSS 4.9
CVE-2023-41779 MEDIUM
ZTE ZXCLOUD iRAI < 7.23.32 - Authenticated Denial of Service via Illegal Memory Access
CVSS 4.4
CVE-2023-52077 HIGH
Nexkey <12.23Q4.5 - Privilege Escalation
CVSS 8.9
CVE-2023-5644 HIGH
WP Mail Log < 1.1.3 - Incorrect Authorization via REST API Endpoints
CVSS 7.6
CVE-2023-49949 HIGH
Passwork < 6.2.0 - Authenticated 2FA Bypass via Brute-Force Attack
CVSS 8.1
CVE-2023-51649 LOW
Nautobot 1.5.14-1.6.8 - Incorrect Authorization via Job Button Submission
CVSS 3.5
CVE-2023-51380 LOW
GitHub Enterprise Server <3.7.19-3.11.1 - Auth Bypass
CVSS 2.7
CVE-2023-51379 MEDIUM
GitHub Enterprise Server <3.17.19-3.11.1 - Auth Bypass
CVSS 4.9
CVE-2023-50732 HIGH
XWiki 8.3-14.10.6 - Unauthenticated Velocity Script Execution via Document Tree
CVSS 8.3
CVE-2023-7047 MEDIUM
Devolutions Remote Desktop Manager < 2023.3.31.0 - Incorrect Authorization via Remote Tools Context Menu
CVSS 4.4
CVE-2023-50705 MEDIUM
Efacec UC 500e Firmware - Information Disclosure
CVSS 5.3
CVE-2023-49734 HIGH
Apache Superset < 2.1.2, 3.0.0-3.0.1 - Authenticated Incorrect Authorization via Dashboard Chart Ownership
CVSS 7.7
CVE-2023-6355 MEDIUM
Gallagher Controller 7000 <9.00.231204b - Privilege Escalation
CVSS 6.8
CVE-2023-41314 HIGH
Apache Doris < 2.0.3 - Unauthenticated Arbitrary File Read and Denial of Service via Snapshot and Log File API
CVSS 8.2
CVE-2023-3511 LOW
GitLab EE <16.4.4-16.6.2 - Info Disclosure
CVSS 2.0
CVE-2023-6837 HIGH
WSO2 API Manager 2.5.0-2.5.0.31 - User Impersonation via JIT Provisioning
CVSS 8.5
CVE-2023-45185 HIGH
IBM i Access Client Solutions 1.1.2-1.1.4 and 1.1.4.3-1.1.9.3 - Remote Code Execution via Improper Authority Checks
CVSS 7.4
CVE-2023-50777 MEDIUM
Jenkins PaaSLane Estimate Plugin <= 1.0.4 - Cleartext Storage of Sensitive Information
CVSS 4.3
CVE-2023-47320 HIGH
Silverpeas Core < 6.3.2 - Authenticated Denial of Service via Maintenance Mode Function
CVSS 8.1
CVE-2023-49273 MEDIUM
Umbraco <8.0.0-8.18.10-10.8.1-12.3.4 - Info Disclosure
CVSS 5.4
CVE-2023-48227 MEDIUM
Umbraco CMS 8.0.0-8.18.9 - Incorrect Authorization
CVSS 4.3
Details
Vulnerabilities 3,087
Exploit Likelihood High