The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,088 vulnerabilities with CWE-863
CVE-2023-2759
HIGH
TapHome core_firmware < 2023.2 - Authenticated Incorrect Authorization via Hidden API
CVSS 8.8
CVE-2023-31704
CRITICAL
Sourcecodester Online Computer and Laptop Store 1.0 - Incorrect Authorization
CVSS 9.8
CVE-2023-3444
MEDIUM
GitLab 15.3-15.11.9, 16.0-16.0.5, 16.1 - Incorrect Authorization in Protected Branch Merge
CVSS 5.7
CVE-2023-2576
MEDIUM
GitLab 13.7-15.11.9, 16.0-16.0.5, 16.1 - Incorrect Authorization in CODEOWNERS Rule Removal
CVSS 4.3
CVE-2023-21256
HIGH
Android - Local Privilege Escalation via SettingsHomepageActivity Logic Error
CVSS 7.8
CVE-2023-21254
HIGH
Android - Incorrect Authorization in OneTimePermissionUserManager
CVSS 7.8
CVE-2023-21245
HIGH
Android - Local Privilege Escalation via KeyguardSecurityContainerController Logic Error
CVSS 7.8
CVE-2023-37579
HIGH
Apache Pulsar < 2.10.4 and 2.11.0 - Authenticated Credential Leak via Function Worker Source/Sink Configuration
CVSS 8.2
CVE-2023-35908
MEDIUM
Apache Airflow <2.6.3 - Info Disclosure
CVSS 6.5
CVE-2023-30429
CRITICAL
Apache Pulsar < 2.10.4 and 2.11.0 - Incorrect Authorization via Pulsar Function Worker
CVSS 9.6
CVE-2023-30428
HIGH
Apache Pulsar 2.9.0-2.9.5, 2.10.0-2.10.3, 2.11.0 - Incorrect Authorization via Rest Producer
CVSS 8.2
CVE-2023-36994
CRITICAL
TravianZ <8.3.4-8.3.3 - Code Injection
CVSS 9.8
CVE-2023-34197
MEDIUM
Zoho ManageEngine <14202-14300 - Privilege Escalation
CVSS 5.4
CVE-2023-36829
MEDIUM
Sentry 23.6.0-23.6.2 - Permissive Cross-domain Security Policy via Origin Header
CVSS 6.8
CVE-2023-29381
CRITICAL
Zimbra Collaboration <9.0 - Privilege Escalation
CVSS 9.8
CVE-2023-29656
MEDIUM
Darktrace Threat Visualizer 6.0.0-6.0.14 - Incorrect Authorization
CVSS 6.1
CVE-2023-35939
HIGH
GLPI <10.0.8 - Privilege Escalation
CVSS 8.1
CVE-2023-34107
MEDIUM
GLPI 9.2.0-10.0.7 - Authenticated Incorrect Access Control in KnowbaseItems
CVSS 6.5
CVE-2023-34106
MEDIUM
GLPI <10.0.8 - Privilege Escalation
CVSS 6.5
CVE-2023-26258
CRITICAL
Arcserve UDP <9.0.6034 - Auth Bypass
CVSS 9.8
CVE-2023-31997
CRITICAL
UniFi OS 3.1 - Incorrect Authorization in MongoDB Access Control
CVSS 9.0
CVE-2023-3485
LOW
Temporal Server < 1.20.0 - Namespace Access Control Bypass via Crafted Task Token
CVSS 3.0
CVE-2023-37300
MEDIUM
MediaWiki < 1.39.3 - Incorrect Authorization in CheckUserLog API
CVSS 5.3
CVE-2023-33190
CRITICAL
Sealos <4.2.1-rc4 - Privilege Escalation
CVSS 9.9
CVE-2023-30955
MEDIUM
Foundry workspace-server <7.7.0 - Auth Bypass
CVSS 4.3
Details
Vulnerabilities
3,088
Exploit Likelihood
High