The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,098 vulnerabilities with CWE-863
CVE-2023-27899
HIGH
Jenkins < 2.375.4, < 2.394, 2.376-2.387.1 - Arbitrary Code Execution via Plugin Upload Temporary File
CVSS 7.0
CVE-2023-22891
HIGH
SmartBear Zephyr Enterprise <= 7.15.0 - Authenticated Privilege Escalation via Password Reset
CVSS 8.1
CVE-2023-27486
HIGH
xCAT < 2.16.5 - Incorrect Authorization via Zone Configuration
CVSS 8.1
CVE-2023-27485
MEDIUM
thm feedbacksystem < 1.5.3 - Authenticated Incorrect Authorization in Subresults Query
CVSS 4.3
CVE-2023-0328
MEDIUM
WPCode < 2.0.7 - Authenticated Inadequate Privilege Checks in AJAX Actions
CVSS 4.3
CVE-2023-1164
HIGH
KylinOS < 1.3.11-23 and < 1.30.10-5.p23 - Improper Authorization in File Import
CVSS 8.4
CVE-2023-26056
MEDIUM
XWiki Platform <3.0-milestone-1 - Privilege Escalation
CVSS 5.4
CVE-2023-0952
MEDIUM
Devolutions Server < 2022.3.12 - Authenticated Sensitive Data Exposure via Improper Access Controls
CVSS 6.5
CVE-2023-25575
HIGH
API Platform Core 2.7-2.7.9 3.0-3.0.11 - Unauthorized Data Disclosure via Security Rule Caching
CVSS 7.7
CVE-2023-23510
MEDIUM
macOS < 13.2 - Unprotected User Data Exposure via Safari History Access
CVSS 5.5
CVE-2023-23506
MEDIUM
macOS < 13.2 - Unprotected User Data Exposure via Permissions Issue
CVSS 5.5
CVE-2023-23918
HIGH
Node.js <19.6.1, <18.14.1, <16.19.1, <14.21.3 - Privilege Escalation
CVSS 7.5
CVE-2023-23064
CRITICAL
TOTOLINK A720R V4.1.5cu.532_B20210610 - Incorrect Access Control
CVSS 9.8
CVE-2023-24485
HIGH
Citrix Workspace app - Privilege Escalation
CVSS 7.8
CVE-2023-23947
CRITICAL
Argo CD <2.3.17, <2.4.23, <2.5.11, <2.6.2 - Privilege Escalation
CVSS 9.1
CVE-2023-25173
MEDIUM
containerd < 1.5.18 - Incorrect Authorization via Supplementary Group Handling
CVSS 5.3
CVE-2023-21715
HIGH
KEV
Microsoft Publisher - Privilege Escalation
CVSS 7.3
CVE-2023-0814
MEDIUM
Profile Builder < 3.9.0 - Authenticated Sensitive Information Exposure via User Meta Shortcode
CVSS 6.5
CVE-2023-25559
HIGH
DataHub < 0.8.45 - Unauthenticated Authorization Bypass via HTTP Header Case Smuggling
CVSS 8.2
CVE-2023-21424
MEDIUM
Samsung Android - Improper Authorization in SemChameleonHelper
CVSS 5.1
CVE-2023-21423
MEDIUM
Samsung Android ChnFileShareKit - Improper Authorization via BLE Advertising Control
CVSS 5.1
CVE-2023-21422
MEDIUM
Samsung Android - Improper Authorization in WifiService semAddPublicDnsAddr
CVSS 5.7
CVE-2023-23696
HIGH
Dell Command Intel vPro Out of Band < 4.4.0 - Authenticated Arbitrary File Write
CVSS 7.0
CVE-2023-24029
HIGH
WS_FTP Server <8.8 - Privilege Escalation
CVSS 7.2
CVE-2023-23751
MEDIUM
Joomla! 4.0.0-4.2.4 - Incorrect Authorization in com_actionlogs
CVSS 4.3
Details
Vulnerabilities
3,098
Exploit Likelihood
High