CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,088 vulnerabilities with CWE-863
CVE-2023-21225 HIGH
Android - Local Privilege Escalation via Protected Confirmation Screen Bypass
CVSS 7.8
CVE-2023-22593 MEDIUM
IBM Robotic Process Automation 21.0.1-21.0.7.3 & 23.0.0-23.0.3 Privilege Escalation via Redis Misconfiguration
CVSS 4.0
CVE-2023-34148 HIGH
Trend Micro Apex One/Apex One as a Service - Privilege Escalation
CVSS 7.8
CVE-2023-34147 HIGH
Trend Micro Apex One/Apex One as a Service - Privilege Escalation
CVSS 7.8
CVE-2023-34146 HIGH
Trend Micro Apex One/Apex One as a Service - Privilege Escalation
CVSS 7.8
CVE-2023-35165 MEDIUM
AWS Cloud Development Kit 1.57.0-1.202.0 and 2.0.0-2.80.0 - Incorrect Authorization via Overly Permissive Trust Policy
CVSS 6.6
CVE-2023-32353 HIGH
iTunes < 12.12.9 - Privilege Escalation
CVSS 7.8
CVE-2023-3114 MEDIUM
Terraform Enterprise <202306-1 - Privilege Escalation
CVSS 5.0
CVE-2023-34923 HIGH
TOPdesk 12.10.12 - Authenticated User Impersonation via SAML Response Manipulation
CVSS 8.1
CVE-2023-29708 HIGH
WavLink WavRouter RPT70HA1.x - Unauthenticated Factory Reset via adm.cgi
CVSS 7.5
CVE-2023-0971 CRITICAL
SiLabs Z/IP Gateway SDK < 7.18.01 - Authentication Bypass and Privilege Escalation
CVSS 9.6
CVE-2023-35166 CRITICAL
XWiki 8.1-14.10.5 - Incorrect Authorization via Tip UI Extension
CVSS 9.9
CVE-2023-34161 HIGH
Huawei EMUI - Incorrect Authorization in SettingsProvider Module
CVSS 7.5
CVE-2023-35866 MEDIUM
KeePassXC < 2.7.5 - Unauthenticated Database Security Settings Modification
CVSS 5.5
CVE-2023-25185 LOW
NOKIA Airscale ASIKA Single RAN < 21B - Improper Privilege Management
CVSS 3.8
CVE-2023-29296 MEDIUM
Adobe Commerce <2.4.6 - Auth Bypass
CVSS 4.3
CVE-2023-29295 MEDIUM
Adobe Commerce <2.4.6 - Auth Bypass
CVSS 4.3
CVE-2023-29288 MEDIUM
Adobe Commerce <2.4.6 - Auth Bypass
CVSS 4.3
CVE-2023-22248 HIGH
Adobe Commerce <2.4.6 - Auth Bypass
CVSS 7.5
CVE-2023-28175 HIGH
Bosch Video Management System 11.0-11.1.1 - Authenticated Internal Network Access via SSH Port Forwarding
CVSS 7.1
CVE-2023-32061 MEDIUM
Discourse < 3.0.4 - Unauthenticated Comment Hiding via iFrame Tag
CVSS 5.4
CVE-2023-24546 HIGH
Arista CloudVision Portal - Info Disclosure
CVSS 8.1
CVE-2023-34965 MEDIUM
SSPanel-Uim 2023.3 - Incorrect Authorization in /link/ Interface
CVSS 5.3
CVE-2023-32220 HIGH
Milesight NCR/camera_firmware 71.8.0.6-r5 - Authentication Bypass
CVSS 8.2
CVE-2023-32219 MEDIUM
Mazda Firmware - Unauthenticated Vehicle Unlock
CVSS 6.5
Details
Vulnerabilities 3,088
Exploit Likelihood High