CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,088 vulnerabilities with CWE-863
CVE-2023-36092 CRITICAL
D-Link DIR-859 FW105b03 - Privilege Escalation
CVSS 9.8
CVE-2023-36091 CRITICAL
D-Link DIR-895 FW102b07 - Privilege Escalation
CVSS 9.8
CVE-2023-36090 CRITICAL
D-Link DIR-885L FW102b01 - Privilege Escalation
CVSS 9.8
CVE-2023-36089 CRITICAL
D-Link DIR-645 <1.03 - Privilege Escalation
CVSS 9.8
CVE-2023-38488 HIGH
Kirby <3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, 3.9.6 - Field Injection
CVSS 7.1
CVE-2023-3957 MEDIUM
ACF Photo Gallery Field <= 1.9 - Authenticated Arbitrary User Meta Update via apg_profile_update
CVSS 4.3
CVE-2023-35983 MEDIUM
macOS 11.0-11.7.8 - Unprotected File System Modification
CVSS 5.5
CVE-2023-39154 MEDIUM
Jenkins Qualys Web App Scanning Connector < 2.0.10 - Incorrect Authorization via URL Connection
CVSS 6.5
CVE-2023-32629 HIGH
Ubuntu Linux - Local Privilege Escalation via OverlayFS Permission Check Bypass
CVSS 7.8
CVE-2023-2640 HIGH
GameOver(lay) Privilege Escalation and Container Escape
CVSS 7.8
CVE-2023-38503 MEDIUM
Directus 10.3.0-10.5.0 - Unauthorized Data Exposure via GraphQL Subscription Permission Bypass
CVSS 5.7
CVE-2023-38493 HIGH
Armeria < 1.24.3 - Incorrect Authorization via Matrix Variable Bypass
CVSS 7.5
CVE-2023-36826 HIGH
Sentry 8.21.0-23.5.2 - Authenticated Improper Authorization via Debug/Artifact Bundle Download
CVSS 7.7
CVE-2023-38058 MEDIUM
OTRS 8.0.0-8.0.34 - Authenticated Improper Privilege Management in Ticket Move Action
CVSS 4.1
CVE-2023-36339 HIGH
WebBoss.io CMS <3.7.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-3484 HIGH
GitLab 12.8.0-15.11.10, 16.0.0-16.0.6, 16.1.0-16.1.1 - Incorrect Authorization
CVSS 8.0
CVE-2023-32482 MEDIUM
Dell Wyse Management Suite < 4.0 - Authenticated Improper Authorization
CVSS 4.9
CVE-2023-32261 MEDIUM
Micro Focus Dimensions CM Plugin for Jenkins < 0.9.3.1 - Credential ID Enumeration via Overall/Read Permission
CVSS 4.2
CVE-2023-34035 HIGH
Spring Security <5.8.5,6.0.5,6.1.2 - Info Disclosure
CVSS 7.3
CVE-2023-3459 HIGH
WordPress Export & Import Users/Cust <2.4.1 - Info Disclosure
CVSS 7.2
CVE-2023-3613 LOW
Mattermost WelcomeBot - Privilege Escalation
CVSS 3.5
CVE-2023-3590 LOW
Mattermost 7.10.0-7.10.2 - Incorrect Authorization in Boards Card Attachment Deletion
CVSS 3.1
CVE-2023-3586 MEDIUM
Mattermost 7.8.0-7.8.6 - Incorrect Authorization via Public Boards Configuration
CVSS 4.2
CVE-2023-3584 LOW
Mattermost 7.8.0-7.8.4 - Authenticated Incorrect Authorization via Team Override Scheme ID
CVSS 3.1
CVE-2023-3582 MEDIUM
Mattermost 7.8.0-7.8.6 - Authenticated Incorrect Authorization via Board Channel Linking
CVSS 4.3
Details
Vulnerabilities 3,088
Exploit Likelihood High