CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,098 vulnerabilities with CWE-863
CVE-2022-47553 HIGH
Ormazabal ekorRCI and ekorCCP Firmware - Unauthenticated Sensitive Information Exposure
CVSS 8.6
CVE-2022-48538 MEDIUM
Cacti 1.2.19 - Authentication Bypass via Zero Password
CVSS 5.3
CVE-2022-29871 MEDIUM
Intel Converged Security Management Engine Firmware < 11.12.94 - Authenticated Privilege Escalation via Local Access
CVSS 6.7
CVE-2022-26563 HIGH
Tildeslash Monit <5.31.0 - Privilege Escalation
CVSS 8.8
CVE-2022-48508 HIGH
Huawei EMUI and HarmonyOS - Inappropriate Authorization Affecting Service Integrity
CVSS 7.5
CVE-2022-46080 CRITICAL
Nexxt Nebula 1200-AC <15.03.06.60 - Auth Bypass, Command Injection
CVSS 9.8
CVE-2022-48495 MEDIUM
Huawei EMUI - Unauthorized Access to Foreground App Information
CVSS 5.3
CVE-2022-48488 MEDIUM
Huawei EMUI - Incorrect Authorization Bypass via Default Desktop Security Controls
CVSS 5.3
CVE-2022-22307 MEDIUM
IBM Security Guardium <11.6 - Privilege Escalation
CVSS 4.4
CVE-2022-31646 HIGH
HP Dragonfly Folio G3 2-in-1 Firmware - Incorrect Authorization
CVSS 7.8
CVE-2022-31644 HIGH
HP PC Products - RCE, Privilege Escalation, DoS, Info Disclosure
CVSS 7.8
CVE-2022-40529 HIGH
Qualcomm AQT1000 Firmware - Memory Corruption via Improper Access Control in Kernel Mapping
CVSS 7.1
CVE-2022-46308 HIGH
SGUDA U-Lock - Privilege Escalation
CVSS 8.8
CVE-2022-46307 HIGH
SGUDA U-Lock Firmware - Incorrect Authorization in Lock Management Function
CVSS 8.8
CVE-2022-45128 MEDIUM
Intel Endpoint Management Assistant < 1.9.0.0 - Authenticated Denial of Service via Local Access
CVSS 5.0
CVE-2022-43465 MEDIUM
Intel Setup and Configuration Software - Authenticated Denial of Service via Local Access
CVSS 5.0
CVE-2022-41610 MEDIUM
Intel(R) EMA Config Tool <1.0.4 & Intel(R) MC <2.4 - DoS
CVSS 5.0
CVE-2022-47874 MEDIUM
Jedox Cloud 2020.2.5 - Authenticated Database Credential Disclosure via /tc/rpc Connections Endpoint
CVSS 6.5
CVE-2022-25091 MEDIUM
Infopop Ultimate Bulletin Board <= 5.47a - Unauthenticated Private Message Disclosure via Quote Reply Feature
CVSS 5.3
CVE-2022-37326 HIGH
Docker Desktop < 4.6.0 - Unauthenticated Arbitrary File Deletion via WindowsContainerStartRequest DaemonJSON pidfile
CVSS 7.8
CVE-2022-25274 MEDIUM
Drupal 9.3.0-9.3.11 - Incorrect Authorization in Entity Revision Access API
CVSS 5.4
CVE-2022-40682 HIGH
FortiClient 6.0.0-6.0.10, 6.2.0-6.2.9, 6.4.0-6.4.9, 7.0.0-7.0.7 - RCE via Named Pipe
CVSS 7.8
CVE-2022-43770 MEDIUM
Hitachi Vantara Pentaho Business Analytics Server <9.3.0.0-8.3.0.27...
CVSS 5.4
CVE-2022-43940 HIGH
Hitachi Vantara Pentaho <9.4.0.1-9.3.0.2 - Auth Bypass
CVSS 8.8
CVE-2022-27642 HIGH
NETGEAR Multiple Router Firmware - Unauthenticated Incorrect Authorization via httpd String Matching
CVSS 8.8
Details
Vulnerabilities 3,098
Exploit Likelihood High