The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,098 vulnerabilities with CWE-863
CVE-2022-1124
MEDIUM
GitLab < 14.8.6, 14.9.0-14.9.4, 14.10.0 - Incorrect Authorization for Job Trace Log Access
CVSS 4.3
CVE-2022-28601
MEDIUM
Simple 2FA Plugin for Moodle - Auth Bypass
CVSS 6.5
CVE-2022-1417
MEDIUM
GitLab 8.12-14.8.5, 14.9-14.9.3, 14.10 - Unauthenticated Project Wiki Access via CI Job
CVSS 4.3
CVE-2022-0866
MEDIUM
JBoss EAP >=7.1.0 and WildFly >=11.0.0 <26.1.1 - Incorrect Authorization via Concurrent RunAs Principal Handling
CVSS 5.3
CVE-2022-1631
HIGH
microweber < 1.2.15 - Unauthenticated Account Takeover via Email Registration
CVSS 8.8
CVE-2022-29176
CRITICAL
rubygems.org - Unauthenticated Gem Removal and Replacement via Yank Action
CVSS 9.9
CVE-2022-0984
MEDIUM
Moodle 3.9.0-3.9.12 and 3.11.0-3.11.5 - Incorrect Authorization in Badge Criteria Configuration
CVSS 4.3
CVE-2022-0985
MEDIUM
moodle <3.9.13 and 3.11.0-3.11.6 - Improper Authentication in User Deletion
CVSS 4.3
CVE-2022-23822
MEDIUM
Zynq-7000 SoC FSBL - Privilege Escalation
CVSS 6.8
CVE-2022-1466
MEDIUM
Redhat Keycloak < 17.0.1 - Incorrect Authorization
CVSS 6.5
CVE-2022-24865
MEDIUM
HumHub < 1.9.4 - Unauthorized Data Exposure via Forced Password Change
CVSS 6.5
CVE-2022-27055
HIGH
ecjia-daojia 1.38.1-20210202629 - Information Leakage via Installer Helper
CVSS 7.5
CVE-2022-24841
MEDIUM
fleetdm/fleet < 4.13 - Authorization Bypass via Team Admin Privilege Escalation
CVSS 6.5
CVE-2022-1365
MEDIUM
cross-fetch < 3.1.5 - Exposure of Private Personal Information
CVSS 6.5
CVE-2022-29047
MEDIUM
Jenkins Pipeline: Shared Groovy Libraries Plugin <2.21.3 - Code Inj...
CVSS 5.3
CVE-2022-28542
MEDIUM
Galaxy Store <4.5.40.5 - Privilege Escalation
CVSS 6.8
CVE-2022-27836
HIGH
Android Storage Manager < SMR Apr-2022 Release 1 - Improper Access Control and Path Traversal
CVSS 8.4
CVE-2022-27575
LOW
Google Android - Information Disclosure
CVSS 3.3
CVE-2022-1193
MEDIUM
GitLab 10.7-14.7.7, 14.8-14.8.5, 14.9-14.9.2 - Unauthenticated Improper Access Control via Merge Requests
CVSS 4.3
CVE-2022-0920
HIGH
Salon booking system Free and Pro < 7.6.3 - Unauthenticated Incorrect Authorization
CVSS 7.5
CVE-2022-26676
CRITICAL
aEnrich a+HRD - Unauthenticated Arbitrary File Upload and Remote Code Execution via API Function
CVSS 9.8
CVE-2022-27609
MEDIUM
Forcepoint One Endpoint < 22.01 - Insufficient Anti-Tampering Protection
CVSS 6.0
CVE-2022-27608
MEDIUM
Forcepoint One Endpoint < 22.01 - Registry Key Tampering via Anti-Tampering Mechanism
CVSS 6.0
CVE-2022-0740
LOW
GitLab CE/EE <14.7.7-14.9.2 - Auth Bypass
CVSS 3.1
CVE-2022-0825
MEDIUM
Amelia < 1.0.49 - Incorrect Authorization in Appointment Management
CVSS 5.4
Details
Vulnerabilities
3,098
Exploit Likelihood
High