The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,088 vulnerabilities with CWE-863
CVE-2023-46125
MEDIUM
Fides < 2.22.1 - Unauthorized Exposure of Sensitive Configuration via API Endpoint
CVSS 6.5
CVE-2023-43961
HIGH
Dromara SaToken <1.3.50RC - Auth Bypass
CVSS 8.8
CVE-2023-43508
MEDIUM
ClearPass Policy Manager - Privilege Escalation
CVSS 6.3
CVE-2023-34051
CRITICAL
VMware Aria Operations for Logs - RCE
CVSS 9.8
CVE-2023-22067
MEDIUM
Oracle Java SE <8u381-21.3.7 - Unauthorized Update
CVSS 5.3
CVE-2023-43119
CRITICAL
Extreme Networks Switch Engine <32.5.1.5 - Privilege Escalation
CVSS 9.8
CVE-2023-29484
MEDIUM
Terminalfour < 8.3.16 - Incorrect Authorization via LDAP Misconfiguration
CVSS 6.5
CVE-2023-38218
HIGH
Adobe Commerce <=2.4.7-beta1, <=2.4.6-p2, <=2.4.5-p4, <=2.4.4-p5 - Authenticated Info Exposure & Privilege Escalation
CVSS 8.8
CVE-2023-40829
HIGH
Tencent Enterprise Wechat Privatization <2.6.930000 - Info Disclosure
CVSS 7.5
CVE-2023-41882
MEDIUM
vantage6 < 4.0.0 - Improper Access Control in Task Collection Endpoint
CVSS 5.4
CVE-2023-35653
MEDIUM
Google Android - Incorrect Authorization
CVSS 4.4
CVE-2023-28635
MEDIUM
vantage6 < 4.0.0 - Incorrect Authorization via Integer Resource Name
CVSS 5.4
CVE-2023-5521
CRITICAL
kernelsu < 0.6.9 - Incorrect Authorization
CVSS 9.8
CVE-2023-36556
HIGH
FortiMail 6.0.0-6.0.11, 7.0.0-7.0.5, 7.2.0-7.2.2 - Authenticated Incorrect Authorization via Crafted HTTP Requests
CVSS 8.8
CVE-2023-44860
HIGH
NETIS SYSTEMS N3Mv2 1.0.1.865 - Denial of Service via Authorization Component
CVSS 7.5
CVE-2023-1832
MEDIUM
Candlepin < 4.3.7-3 - Improper Access Control
CVSS 6.8
CVE-2023-4997
HIGH
ProIntegra Uptime DC < 2.0.0.33940 - Authenticated Privilege Escalation via Password Change
CVSS 8.8
CVE-2023-5106
HIGH
GitLab EE <16.2.8-16.4.1 - Privilege Escalation
CVSS 8.2
CVE-2023-5195
MEDIUM
Mattermost 7.0.0-7.8.9 and 8.1.0 - Incorrect Authorization in Team Soft Delete
CVSS 6.5
CVE-2023-5194
LOW
Mattermost 7.0.0-7.8.9 and 8.1.0 - Incorrect Authorization in User Demotion
CVSS 2.7
CVE-2023-5193
MEDIUM
Mattermost 7.0.0-7.8.9 and 8.1.0 - Incorrect Authorization in Direct Message Post Retrieval
CVSS 4.9
CVE-2023-5159
LOW
Mattermost 7.0.0-7.8.9 and 8.1.0 - Incorrect Authorization in Bot Management
CVSS 3.8
CVE-2023-5198
MEDIUM
GitLab <16.2.7, <16.3.5, <16.4.1 - Info Disclosure
CVSS 4.3
CVE-2023-4532
MEDIUM
GitLab <16.2.8-16.4.1 - Info Disclosure
CVSS 4.3
CVE-2023-3979
LOW
GitLab 10.6-16.2.7, 16.3-16.3.4, 16.4 - Incorrect Authorization in Merge Request Source Branch
CVSS 3.1
Details
Vulnerabilities
3,088
Exploit Likelihood
High