CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,098 vulnerabilities with CWE-863
CVE-2022-36009 MEDIUM
gomatrixserverlib - Info Disclosure
CVSS 5.0
CVE-2022-1401 MEDIUM
Device42 CMDB < 18.01.00 - Unauthenticated Sensitive File Read via Exago Image Resource Endpoint
CVSS 6.9
CVE-2022-34255 HIGH
Adobe Commerce <2.4.3-p2, 2.3.7-p3, 2.4.4 - Privilege Escalation
CVSS 8.8
CVE-2022-2354 HIGH
WP-DBManager <2.80.8 - Command Injection
CVSS 7.2
CVE-2022-35487 HIGH
Zammad 5.2.0 - Unauthenticated Incorrect Access Control in Attachment Endpoints
CVSS 7.5
CVE-2022-33718 MEDIUM
Wi-Fi Service <SMR AUG-2022 Release 1 - Info Disclosure
CVSS 6.2
CVE-2022-2501 MEDIUM
GitLab EE <15.0.5-15.2.1 - Auth Bypass
CVSS 5.9
CVE-2022-2326 MEDIUM
GitLab CE/EE <15.0.5, <15.1.4, <15.2.1 - Info Disclosure
CVSS 6.4
CVE-2022-2095 MEDIUM
GitLab 13.7-15.0.4, 15.1-15.1.3, 15.2 - Authenticated Deploy Key Information Disclosure
CVSS 4.3
CVE-2022-27551 MEDIUM
HCL Launch 7.0.0.0-7.0.5.11 - Authenticated Sensitive Information Exposure via Improper Security Checking
CVSS 5.3
CVE-2022-35924 CRITICAL
NextAuth.js <4.10.3, 3.29.10 - Info Disclosure
CVSS 9.1
CVE-2022-35921 LOW
fof/byobu 0.3.0-beta.2-1.1.6 - Improper Privilege Management
CVSS 3.5
CVE-2022-31190 MEDIUM
DSpace 4.0-6.3 - Exposure of Sensitive Information via XMLUI mets.xml
CVSS 5.3
CVE-2022-31178 MEDIUM
elabftw < 4.3.4 - Authenticated Incorrect Authorization
CVSS 4.3
CVE-2022-31155 MEDIUM
Sourcegraph <3.41.0 - Info Disclosure
CVSS 4.3
CVE-2022-31154 MEDIUM
Sourcegraph <3.42 - Privilege Escalation
CVSS 6.4
CVE-2022-35716 MEDIUM
IBM UrbanCode Deploy <7.2.3.0 - Info Disclosure
CVSS 6.5
CVE-2022-22326 LOW
IBM Datapower Gateway - Info Disclosure
CVSS 3.3
CVE-2022-1499 MEDIUM
Google Chrome < 101.0.4951.41 - Same Origin Policy Bypass via WebAuthentication
CVSS 6.3
CVE-2022-1309 CRITICAL
Google Chrome < 100.0.4896.88 - Sandbox Escape via Developer Tools Policy Bypass
CVSS 9.6
CVE-2022-0670 CRITICAL
Openstack manilla - Info Disclosure
CVSS 9.1
CVE-2022-0594 MEDIUM
shareaholic < 9.7.6 - Unauthenticated Information Disclosure via AJAX Action
CVSS 5.3
CVE-2022-1132 MEDIUM
Google Chrome < 100.0.4896.60 - Incorrect Authorization via Virtual Keyboard
CVSS 6.1
CVE-2022-31168 MEDIUM
Zulip Server <5.5 - Privilege Escalation
CVSS 5.4
CVE-2022-34046 HIGH
Wavlink WN533A8 M33A8.V5030.190716 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 3,098
Exploit Likelihood High