CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,088 vulnerabilities with CWE-863
CVE-2023-27716 CRITICAL
kafkaui-lite 1.2.11 - Incorrect Authorization
CVSS 9.8
CVE-2023-29766 HIGH
CrossX 1.15.3 - Privilege Escalation via Database Files
CVSS 7.8
CVE-2023-29761 MEDIUM
Sleep 20230303 - Unauthenticated Denial of Service via SharedPreference Manipulation
CVSS 5.5
CVE-2023-29759 MEDIUM
FlightAware 5.8.0 - Unauthorized Persistent Denial of Service via Database Manipulation
CVSS 5.5
CVE-2023-29758 MEDIUM
Blue Light Filter 1.5.5 - Unauthorized Denial of Service via SharedPreference Manipulation
CVSS 5.5
CVE-2023-29752 HIGH
Facemoji Emoji Keyboard 2.9.1.2 - Incorrect Authorization
CVSS 7.8
CVE-2023-32749 HIGH
Pydio Cells < 3.0.12 - Unauthenticated Privilege Escalation via External User Role Assignment
CVSS 8.8
CVE-2023-34958 MEDIUM
Chamilo LMS 1.11.0-1.11.18 - Incorrect Authorization in Student Document Download
CVSS 4.3
CVE-2023-33651 HIGH
Sitecore XP/XM/XC <13.0 - Auth Bypass
CVSS 7.5
CVE-2023-32683 LOW
Synapse < 1.85.0 - Server-Side Request Forgery via URL Preview Bypass
CVSS 3.5
CVE-2023-22833 HIGH
Palantir Foundry 2.519.0-2.531.0 - Authenticated Access Control Bypass
CVSS 7.6
CVE-2023-1779 MEDIUM
MB Connect Lines <2.13.3 - Info Disclosure
CVSS 4.3
CVE-2023-21670 HIGH
GPU Subsystem < Privileged Mode - Command Injection
CVSS 7.8
CVE-2023-3027 HIGH
Grc-policy-propagator - Privilege Escalation
CVSS 7.8
CVE-2023-3066 HIGH
Mobatime mobile app <1.3.20 - Auth Bypass
CVSS 8.1
CVE-2023-25749 MEDIUM
Firefox < 111.0 - Incorrect Authorization via Intent Launch Confirmation Bypass
CVSS 4.3
CVE-2023-25729 HIGH
Firefox < 110.0, Firefox ESR < 102.8, Thunderbird < 102.8 - Incorrect Authorization via ExpandedPrincipals
CVSS 8.8
CVE-2023-23604 MEDIUM
Firefox < 109.0 - Incorrect Authorization via DOMParser SystemPrincipal Bypass
CVSS 6.5
CVE-2023-3033 MEDIUM
Mobatime <6.7.22 - Privilege Escalation
CVSS 6.8
CVE-2023-28698 CRITICAL
Wade Graphic Design FANTSY - Privilege Escalation
CVSS 9.8
CVE-2023-34219 MEDIUM
JetBrains TeamCity < 2023.05 - Improper Authorization via REST API
CVSS 4.3
CVE-2023-34218 CRITICAL
JetBrains TeamCity < 2023.05 - Incorrect Authorization Bypass
CVSS 9.1
CVE-2023-28352 HIGH
Faronics Insight 10.0.19045 - Incorrect Authorization via UDP Broadcast Discovery
CVSS 7.4
CVE-2023-24600 MEDIUM
OX App Suite <7.10.6-rev37 - Auth Bypass
CVSS 4.3
CVE-2023-33779 HIGH
XXL-Job <2.4.1 - Privilege Escalation
CVSS 8.8
Details
Vulnerabilities 3,088
Exploit Likelihood High