CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,088 vulnerabilities with CWE-863
CVE-2023-3899 HIGH
subscription-manager - Privilege Escalation
CVSS 7.8
CVE-2023-38035 CRITICAL KEV
Ivanti Sentry MICSLogService Auth Bypass resulting in RCE (CVE-2023-38035)
CVSS 9.8
CVE-2023-40315 MEDIUM
OpenNMS Horizon Authenticated RCE
CVSS 5.3
CVE-2023-40168 HIGH
TurboWarp Desktop < 1.8.0 - Arbitrary File Read via Malicious Project or Extension
CVSS 7.4
CVE-2023-25647 MEDIUM
ZTE Axon 30/40 Pro/40 Ultra, Nubia Z50 Firmware < 3.0.0b06/1.0.0b16/2.0.0b17/1.0.0b19mr - Privilege Escalation
CVSS 4.7
CVE-2023-33237 HIGH
TN-5900 Series firmware <3.3 - Auth Bypass
CVSS 8.8
CVE-2023-32748 CRITICAL
Mitel MiVoice Connect < 22.24.1500.0 - Unauthenticated Arbitrary Script Execution in Linux DVS Server
CVSS 9.8
CVE-2023-39384 HIGH
Huawei EMUI and HarmonyOS - Incomplete Permission Verification in Input Method Module
CVSS 7.5
CVE-2023-4107 MEDIUM
Mattermost 7.8.0-7.8.7 - Incorrect Authorization in User Permission Validation
CVSS 6.7
CVE-2023-28714 HIGH
Intel PROSet/Wireless <22.220 HF - Privilege Escalation
CVSS 8.2
CVE-2023-39965 MEDIUM
1Panel 1.4.3-<1.5.0 - Authenticated Arbitrary File Read via API Interface
CVSS 6.5
CVE-2023-30705 MEDIUM
Samsung Galaxy Store < 4.5.56.6 - Incorrect Authorization via Intent Sanitization Issue
CVSS 6.8
CVE-2023-33468 CRITICAL
KramerAV VIA Connect/VIA Go <4.0.1.1326 - RCE
CVSS 9.1
CVE-2023-24471 MEDIUM
Nozomi Networks CMC and Guardian < 22.6.2 - Authenticated Information Disclosure via Debug Functionality
CVSS 6.5
CVE-2023-38209 MEDIUM
Adobe Commerce <= 2.4.6-p1, <= 2.4.5-p3, <= 2.4.4-p4 - Incorrect Authorization
CVSS 6.5
CVE-2023-4242 MEDIUM
FULL Customer plugin for WordPress <2.2.4 - Info Disclosure
CVSS 4.3
CVE-2023-37492 MEDIUM
SAP NetWeaver Application Server ABAP - Missing Authorization Checks
CVSS 4.9
CVE-2023-37491 HIGH
SAP Message Server - Incorrect Authorization
CVSS 7.5
CVE-2023-39363 MEDIUM
vyper 0.2.15-0.3.0 - Incorrect Authorization via Named Re-entrancy Lock Allocation
CVSS 5.9
CVE-2023-32783 HIGH
Zoho ManageEngine ADAudit Plus 7.1.1 - Audit Detection Bypass via User Account Name Suffix
CVSS 7.5
CVE-2023-4194 MEDIUM
Linux Kernel < 6.4 - Unauthorized Resource Access via TUN/TAP Socket UID Initialization
CVSS 5.5
CVE-2023-20800 MEDIUM
Linuxfoundation Yocto - Incorrect Authorization
CVSS 6.5
CVE-2023-28468 MEDIUM
Insyde Kernel 5.0-5.5 - Incorrect Authorization in FvbServicesRuntimeDxe SMM Module
CVSS 6.5
CVE-2023-38958 MEDIUM
ZKTeco BioAccess IVS 3.3.1 - Unauthenticated Access Control Bypass via Crafted Web Request
CVSS 5.3
CVE-2023-23476 LOW
IBM Robotic Process Automation 21.0.0-21.0.7.latest - Unauthorized Data Access via Insufficient API Authorization
CVSS 3.1
Details
Vulnerabilities 3,088
Exploit Likelihood High