The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,098 vulnerabilities with CWE-863
CVE-2022-36009
MEDIUM
gomatrixserverlib - Info Disclosure
CVSS 5.0
CVE-2022-1401
MEDIUM
Device42 CMDB < 18.01.00 - Unauthenticated Sensitive File Read via Exago Image Resource Endpoint
CVSS 6.9
CVE-2022-34255
HIGH
Adobe Commerce <2.4.3-p2, 2.3.7-p3, 2.4.4 - Privilege Escalation
CVSS 8.8
CVE-2022-2354
HIGH
WP-DBManager <2.80.8 - Command Injection
CVSS 7.2
CVE-2022-35487
HIGH
Zammad 5.2.0 - Unauthenticated Incorrect Access Control in Attachment Endpoints
CVSS 7.5
CVE-2022-33718
MEDIUM
Wi-Fi Service <SMR AUG-2022 Release 1 - Info Disclosure
CVSS 6.2
CVE-2022-2501
MEDIUM
GitLab EE <15.0.5-15.2.1 - Auth Bypass
CVSS 5.9
CVE-2022-2326
MEDIUM
GitLab CE/EE <15.0.5, <15.1.4, <15.2.1 - Info Disclosure
CVSS 6.4
CVE-2022-2095
MEDIUM
GitLab 13.7-15.0.4, 15.1-15.1.3, 15.2 - Authenticated Deploy Key Information Disclosure
CVSS 4.3
CVE-2022-27551
MEDIUM
HCL Launch 7.0.0.0-7.0.5.11 - Authenticated Sensitive Information Exposure via Improper Security Checking
CVSS 5.3
CVE-2022-35924
CRITICAL
NextAuth.js <4.10.3, 3.29.10 - Info Disclosure
CVSS 9.1
CVE-2022-35921
LOW
fof/byobu 0.3.0-beta.2-1.1.6 - Improper Privilege Management
CVSS 3.5
CVE-2022-31190
MEDIUM
DSpace 4.0-6.3 - Exposure of Sensitive Information via XMLUI mets.xml
CVSS 5.3
CVE-2022-31178
MEDIUM
elabftw < 4.3.4 - Authenticated Incorrect Authorization
CVSS 4.3
CVE-2022-31155
MEDIUM
Sourcegraph <3.41.0 - Info Disclosure
CVSS 4.3
CVE-2022-31154
MEDIUM
Sourcegraph <3.42 - Privilege Escalation
CVSS 6.4
CVE-2022-35716
MEDIUM
IBM UrbanCode Deploy <7.2.3.0 - Info Disclosure
CVSS 6.5
CVE-2022-22326
LOW
IBM Datapower Gateway - Info Disclosure
CVSS 3.3
CVE-2022-1499
MEDIUM
Google Chrome < 101.0.4951.41 - Same Origin Policy Bypass via WebAuthentication
CVSS 6.3
CVE-2022-1309
CRITICAL
Google Chrome < 100.0.4896.88 - Sandbox Escape via Developer Tools Policy Bypass
CVSS 9.6
CVE-2022-0670
CRITICAL
Openstack manilla - Info Disclosure
CVSS 9.1
CVE-2022-0594
MEDIUM
shareaholic < 9.7.6 - Unauthenticated Information Disclosure via AJAX Action
CVSS 5.3
CVE-2022-1132
MEDIUM
Google Chrome < 100.0.4896.60 - Incorrect Authorization via Virtual Keyboard
CVSS 6.1
CVE-2022-31168
MEDIUM
Zulip Server <5.5 - Privilege Escalation
CVSS 5.4
CVE-2022-34046
HIGH
Wavlink WN533A8 M33A8.V5030.190716 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
3,098
Exploit Likelihood
High