The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,088 vulnerabilities with CWE-863
CVE-2023-3899
HIGH
subscription-manager - Privilege Escalation
CVSS 7.8
CVE-2023-38035
CRITICAL
KEV
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
CVSS 9.8
CVE-2023-40315
MEDIUM
OpenNMS Horizon Authenticated RCE
CVSS 5.3
CVE-2023-40168
HIGH
TurboWarp Desktop < 1.8.0 - Arbitrary File Read via Malicious Project or Extension
CVSS 7.4
CVE-2023-25647
MEDIUM
ZTE Axon 30/40 Pro/40 Ultra, Nubia Z50 Firmware < 3.0.0b06/1.0.0b16/2.0.0b17/1.0.0b19mr - Privilege Escalation
CVSS 4.7
CVE-2023-33237
HIGH
TN-5900 Series firmware <3.3 - Auth Bypass
CVSS 8.8
CVE-2023-32748
CRITICAL
Mitel MiVoice Connect < 22.24.1500.0 - Unauthenticated Arbitrary Script Execution in Linux DVS Server
CVSS 9.8
CVE-2023-39384
HIGH
Huawei EMUI and HarmonyOS - Incomplete Permission Verification in Input Method Module
CVSS 7.5
CVE-2023-4107
MEDIUM
Mattermost 7.8.0-7.8.7 - Incorrect Authorization in User Permission Validation
CVSS 6.7
CVE-2023-28714
HIGH
Intel PROSet/Wireless <22.220 HF - Privilege Escalation
CVSS 8.2
CVE-2023-39965
MEDIUM
1Panel 1.4.3-<1.5.0 - Authenticated Arbitrary File Read via API Interface
CVSS 6.5
CVE-2023-30705
MEDIUM
Samsung Galaxy Store < 4.5.56.6 - Incorrect Authorization via Intent Sanitization Issue
CVSS 6.8
CVE-2023-33468
CRITICAL
KramerAV VIA Connect/VIA Go <4.0.1.1326 - RCE
CVSS 9.1
CVE-2023-24471
MEDIUM
Nozomi Networks CMC and Guardian < 22.6.2 - Authenticated Information Disclosure via Debug Functionality
CVSS 6.5
CVE-2023-38209
MEDIUM
Adobe Commerce <= 2.4.6-p1, <= 2.4.5-p3, <= 2.4.4-p4 - Incorrect Authorization
CVSS 6.5
CVE-2023-4242
MEDIUM
FULL Customer plugin for WordPress <2.2.4 - Info Disclosure
CVSS 4.3
CVE-2023-37492
MEDIUM
SAP NetWeaver Application Server ABAP - Missing Authorization Checks
CVSS 4.9
CVE-2023-37491
HIGH
SAP Message Server - Incorrect Authorization
CVSS 7.5
CVE-2023-39363
MEDIUM
vyper 0.2.15-0.3.0 - Incorrect Authorization via Named Re-entrancy Lock Allocation
CVSS 5.9
CVE-2023-32783
HIGH
Zoho ManageEngine ADAudit Plus 7.1.1 - Audit Detection Bypass via User Account Name Suffix
CVSS 7.5
CVE-2023-4194
MEDIUM
Linux Kernel < 6.4 - Unauthorized Resource Access via TUN/TAP Socket UID Initialization
CVSS 5.5
CVE-2023-20800
MEDIUM
Linuxfoundation Yocto - Incorrect Authorization
CVSS 6.5
CVE-2023-28468
MEDIUM
Insyde Kernel 5.0-5.5 - Incorrect Authorization in FvbServicesRuntimeDxe SMM Module
CVSS 6.5
CVE-2023-38958
MEDIUM
ZKTeco BioAccess IVS 3.3.1 - Unauthenticated Access Control Bypass via Crafted Web Request
CVSS 5.3
CVE-2023-23476
LOW
IBM Robotic Process Automation 21.0.0-21.0.7.latest - Unauthorized Data Access via Insufficient API Authorization
CVSS 3.1
Details
Vulnerabilities
3,088
Exploit Likelihood
High