The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,098 vulnerabilities with CWE-863
CVE-2022-1224
MEDIUM
phpipam < 1.4.6 - Improper Authorization
CVSS 6.5
CVE-2022-1223
MEDIUM
phpipam < 1.4.6 - Incorrect Authorization
CVSS 6.5
CVE-2022-0406
MEDIUM
GitHub janeczku/calibre-web <0.6.16 - Auth Bypass
CVSS 4.3
CVE-2022-1177
MEDIUM
OpenEMR < 6.1.0 - Insufficient Access Control for Patient Reports
CVSS 4.3
CVE-2022-0720
MEDIUM
Amelia WordPress <1.0.47 - Privilege Escalation
CVSS 5.4
CVE-2022-24783
CRITICAL
Deno 1.18.0-1.20.2 - Unauthenticated Privilege Escalation via Permission Check Bypass
CVSS 10.0
CVE-2022-24778
HIGH
imgcrypt < 1.1.4 - Incorrect Authorization via ManifestList Architecture Handling
CVSS 7.5
CVE-2022-26629
CRITICAL
SoroushPlus+ Messenger <1.0.30 - Auth Bypass
CVSS 9.1
CVE-2022-24730
HIGH
Argo CD <2.1.11, 2.2.6, 2.3.0 - Path Traversal
CVSS 7.7
CVE-2022-0981
HIGH
Quarkus < 2.7.1 - Incorrect Authorization via RestEasy Reactive State Leak
CVSS 8.8
CVE-2022-24755
HIGH
Bareos Director <21.1.0, 20.0.6, 19.2.12 - Auth Bypass
CVSS 8.1
CVE-2022-24721
HIGH
CometD <5.0.11,6.0.6,7.0.6 - Info Disclosure
CVSS 8.1
CVE-2022-24128
HIGH
TimescaleDB <2.5.2 - Privilege Escalation
CVSS 8.0
CVE-2022-0860
CRITICAL
cobbler < 3.3.2 - Improper Authorization
CVSS 9.1
CVE-2022-24609
CRITICAL
Luocms v2.0 - Incorrect Access Control via Template Management
CVSS 9.8
CVE-2022-24748
MEDIUM
Shopware <6.4.8.2 - Info Disclosure
CVSS 6.8
CVE-2022-0482
CRITICAL
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
CVSS 9.1
CVE-2022-24714
MEDIUM
Icinga Web 2 < 2.8.6 - Incorrect Authorization via Role Restrictions with Decommissioned Services
CVSS 5.3
CVE-2022-24306
CRITICAL
Zoho ManageEngine SharePoint Manager Plus <4329 - Privilege Escalation
CVSS 9.8
CVE-2022-0829
HIGH
webmin < 1.990 - Improper Authorization
CVSS 8.1
CVE-2022-0824
HIGH
webmin < 1.990 - Improper Access Control to Remote Code Execution
CVSS 8.8
CVE-2022-0577
MEDIUM
scrapy < 2.6.1 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.5
CVE-2022-0762
MEDIUM
microweber/microweber <1.3 - Info Disclosure
CVSS 5.5
CVE-2022-21706
HIGH
Zulip Server 2.0.0-4.10.0 - Insufficient Access Control via Multi-Use Invitations
CVSS 7.2
CVE-2022-0727
MEDIUM
GitHub chocobozzz/peertube <4.1.0 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities
3,098
Exploit Likelihood
High