CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,088 vulnerabilities with CWE-863
CVE-2023-2759 HIGH
TapHome core_firmware < 2023.2 - Authenticated Incorrect Authorization via Hidden API
CVSS 8.8
CVE-2023-31704 CRITICAL
Sourcecodester Online Computer and Laptop Store 1.0 - Incorrect Authorization
CVSS 9.8
CVE-2023-3444 MEDIUM
GitLab 15.3-15.11.9, 16.0-16.0.5, 16.1 - Incorrect Authorization in Protected Branch Merge
CVSS 5.7
CVE-2023-2576 MEDIUM
GitLab 13.7-15.11.9, 16.0-16.0.5, 16.1 - Incorrect Authorization in CODEOWNERS Rule Removal
CVSS 4.3
CVE-2023-21256 HIGH
Android - Local Privilege Escalation via SettingsHomepageActivity Logic Error
CVSS 7.8
CVE-2023-21254 HIGH
Android - Incorrect Authorization in OneTimePermissionUserManager
CVSS 7.8
CVE-2023-21245 HIGH
Android - Local Privilege Escalation via KeyguardSecurityContainerController Logic Error
CVSS 7.8
CVE-2023-37579 HIGH
Apache Pulsar < 2.10.4 and 2.11.0 - Authenticated Credential Leak via Function Worker Source/Sink Configuration
CVSS 8.2
CVE-2023-35908 MEDIUM
Apache Airflow <2.6.3 - Info Disclosure
CVSS 6.5
CVE-2023-30429 CRITICAL
Apache Pulsar < 2.10.4 and 2.11.0 - Incorrect Authorization via Pulsar Function Worker
CVSS 9.6
CVE-2023-30428 HIGH
Apache Pulsar 2.9.0-2.9.5, 2.10.0-2.10.3, 2.11.0 - Incorrect Authorization via Rest Producer
CVSS 8.2
CVE-2023-36994 CRITICAL
TravianZ <8.3.4-8.3.3 - Code Injection
CVSS 9.8
CVE-2023-34197 MEDIUM
Zoho ManageEngine <14202-14300 - Privilege Escalation
CVSS 5.4
CVE-2023-36829 MEDIUM
Sentry 23.6.0-23.6.2 - Permissive Cross-domain Security Policy via Origin Header
CVSS 6.8
CVE-2023-29381 CRITICAL
Zimbra Collaboration <9.0 - Privilege Escalation
CVSS 9.8
CVE-2023-29656 MEDIUM
Darktrace Threat Visualizer 6.0.0-6.0.14 - Incorrect Authorization
CVSS 6.1
CVE-2023-35939 HIGH
GLPI <10.0.8 - Privilege Escalation
CVSS 8.1
CVE-2023-34107 MEDIUM
GLPI 9.2.0-10.0.7 - Authenticated Incorrect Access Control in KnowbaseItems
CVSS 6.5
CVE-2023-34106 MEDIUM
GLPI <10.0.8 - Privilege Escalation
CVSS 6.5
CVE-2023-26258 CRITICAL
Arcserve UDP <9.0.6034 - Auth Bypass
CVSS 9.8
CVE-2023-31997 CRITICAL
UniFi OS 3.1 - Incorrect Authorization in MongoDB Access Control
CVSS 9.0
CVE-2023-3485 LOW
Temporal Server < 1.20.0 - Namespace Access Control Bypass via Crafted Task Token
CVSS 3.0
CVE-2023-37300 MEDIUM
MediaWiki < 1.39.3 - Incorrect Authorization in CheckUserLog API
CVSS 5.3
CVE-2023-33190 CRITICAL
Sealos <4.2.1-rc4 - Privilege Escalation
CVSS 9.9
CVE-2023-30955 MEDIUM
Foundry workspace-server <7.7.0 - Auth Bypass
CVSS 4.3
Details
Vulnerabilities 3,088
Exploit Likelihood High