The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,088 vulnerabilities with CWE-863
CVE-2023-36092
CRITICAL
D-Link DIR-859 FW105b03 - Privilege Escalation
CVSS 9.8
CVE-2023-36091
CRITICAL
D-Link DIR-895 FW102b07 - Privilege Escalation
CVSS 9.8
CVE-2023-36090
CRITICAL
D-Link DIR-885L FW102b01 - Privilege Escalation
CVSS 9.8
CVE-2023-36089
CRITICAL
D-Link DIR-645 <1.03 - Privilege Escalation
CVSS 9.8
CVE-2023-38488
HIGH
Kirby <3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, 3.9.6 - Field Injection
CVSS 7.1
CVE-2023-3957
MEDIUM
ACF Photo Gallery Field <= 1.9 - Authenticated Arbitrary User Meta Update via apg_profile_update
CVSS 4.3
CVE-2023-35983
MEDIUM
macOS 11.0-11.7.8 - Unprotected File System Modification
CVSS 5.5
CVE-2023-39154
MEDIUM
Jenkins Qualys Web App Scanning Connector < 2.0.10 - Incorrect Authorization via URL Connection
CVSS 6.5
CVE-2023-32629
HIGH
Ubuntu Linux - Local Privilege Escalation via OverlayFS Permission Check Bypass
CVSS 7.8
CVE-2023-2640
HIGH
GameOver(lay) Privilege Escalation and Container Escape
CVSS 7.8
CVE-2023-38503
MEDIUM
Directus 10.3.0-10.5.0 - Unauthorized Data Exposure via GraphQL Subscription Permission Bypass
CVSS 5.7
CVE-2023-38493
HIGH
Armeria < 1.24.3 - Incorrect Authorization via Matrix Variable Bypass
CVSS 7.5
CVE-2023-36826
HIGH
Sentry 8.21.0-23.5.2 - Authenticated Improper Authorization via Debug/Artifact Bundle Download
CVSS 7.7
CVE-2023-38058
MEDIUM
OTRS 8.0.0-8.0.34 - Authenticated Improper Privilege Management in Ticket Move Action
CVSS 4.1
CVE-2023-36339
HIGH
WebBoss.io CMS <3.7.0.1 - Info Disclosure
CVSS 7.5
CVE-2023-3484
HIGH
GitLab 12.8.0-15.11.10, 16.0.0-16.0.6, 16.1.0-16.1.1 - Incorrect Authorization
CVSS 8.0
CVE-2023-32482
MEDIUM
Dell Wyse Management Suite < 4.0 - Authenticated Improper Authorization
CVSS 4.9
CVE-2023-32261
MEDIUM
Micro Focus Dimensions CM Plugin for Jenkins < 0.9.3.1 - Credential ID Enumeration via Overall/Read Permission
CVSS 4.2
CVE-2023-34035
HIGH
Spring Security <5.8.5,6.0.5,6.1.2 - Info Disclosure
CVSS 7.3
CVE-2023-3459
HIGH
WordPress Export & Import Users/Cust <2.4.1 - Info Disclosure
CVSS 7.2
CVE-2023-3613
LOW
Mattermost WelcomeBot - Privilege Escalation
CVSS 3.5
CVE-2023-3590
LOW
Mattermost 7.10.0-7.10.2 - Incorrect Authorization in Boards Card Attachment Deletion
CVSS 3.1
CVE-2023-3586
MEDIUM
Mattermost 7.8.0-7.8.6 - Incorrect Authorization via Public Boards Configuration
CVSS 4.2
CVE-2023-3584
LOW
Mattermost 7.8.0-7.8.4 - Authenticated Incorrect Authorization via Team Override Scheme ID
CVSS 3.1
CVE-2023-3582
MEDIUM
Mattermost 7.8.0-7.8.6 - Authenticated Incorrect Authorization via Board Channel Linking
CVSS 4.3
Details
Vulnerabilities
3,088
Exploit Likelihood
High