The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,098 vulnerabilities with CWE-863
CVE-2023-23924
CRITICAL
dompdf < 2.0.2 - Arbitrary Object Unserialize via SVG Image Tag Bypass
CVSS 10.0
CVE-2023-22610
CRITICAL
EcoStruxure Geo SCADA Expert 2019 - Denial of Service via Database Server TCP Port
CVSS 9.1
CVE-2023-24829
HIGH
Apache IoTDB 0.13.0-0.13.2 - Incorrect Authorization in iotdb-web-workbench
CVSS 8.8
CVE-2023-22500
HIGH
GLPI 10.0.0-10.0.5 - Unauthenticated Inventory File Access via FAQ
CVSS 7.5
CVE-2023-22482
CRITICAL
Argo CD 1.8.2-2.3.12, 2.4.0-2.4.18, 2.5.0-2.5.5 - Incorrect Authorization via OIDC Audience Claim
CVSS 9.0
CVE-2023-21719
MEDIUM
Microsoft Edge Chromium < 109.0.1518.70 - Security Feature Bypass
CVSS 6.5
CVE-2023-20018
HIGH
Cisco IP Phone <7800-8800 - Auth Bypass
CVSS 8.6
CVE-2023-0298
MEDIUM
firefly-iii <5.8.0 - Info Disclosure
CVSS 6.5
CVE-2023-22480
HIGH
KubeOperator < 3.16.4 - Improper Authorization
CVSS 7.3
CVE-2023-0091
LOW
Keycloak - Incorrect Authorization in Client Credential Flow
CVSS 3.8
CVE-2023-22945
MEDIUM
MediaWiki GrowthExperiments < 1.39.0 - Incorrect Authorization in Mentor List Management
CVSS 4.3
CVE-2023-21560
MEDIUM
Windows Boot Manager - Privilege Escalation
CVSS 6.6
CVE-2023-0133
MEDIUM
Google Chrome <109.0.5414.74 - Auth Bypass
CVSS 6.5
CVE-2022-31671
HIGH
Harbor 2.0.0-2.4.2 and 1.0.0-1.10.12 - Authenticated Improper Authorization via P2P Preheat Execution Logs
CVSS 7.4
CVE-2022-31670
HIGH
Harbor 1.0.0-1.10.12 - Authenticated Tag Retention Policy Modification via Permission Bypass
CVSS 7.7
CVE-2022-31669
MEDIUM
Harbor 2.0.0-2.4.2 and 1.0.0-1.10.12 - Authenticated Improper Authorization in Tag Immutability Policy Update
CVSS 6.4
CVE-2022-31668
HIGH
Harbor 2.0.0-2.4.2 - Authenticated Improper Authorization in P2P Preheat Policy Update
CVSS 7.4
CVE-2022-31667
MEDIUM
Harbor 1.0.0-1.10.12 and 2.0.0-2.4.2 - Authenticated Improper Authorization via Robot Account Update
CVSS 6.4
CVE-2022-30358
HIGH
OvalEdge < 5.2.8 - Authenticated Account Takeover via Password Update Endpoint
CVSS 8.8
CVE-2022-30356
MEDIUM
OvalEdge < 5.2.8 - Authenticated Privilege Escalation via User Role Assignment
CVSS 4.7
CVE-2022-45168
MEDIUM
LIVEBOX Collaboration vDesk < 018 - Two-Factor Authentication Bypass via Backup Code Endpoint
CVSS 6.5
CVE-2022-0775
MEDIUM
WooCommerce <6.2.1 - Privilege Escalation
CVSS 4.3
CVE-2022-39337
HIGH
Hertzbeat < 1.2.1 - Unauthenticated Permission Bypass
CVSS 7.5
CVE-2022-40681
HIGH
FortiClient 6.0.0-6.0.10, 6.2.0-6.2.9, 6.4.0-6.4.9, 7.0.0-7.0.7 - Denial of Service via Named Pipe Request
CVSS 7.1
CVE-2022-3248
MEDIUM
OpenShift API - Privilege Escalation
CVSS 4.4
Details
Vulnerabilities
3,098
Exploit Likelihood
High