CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,098 vulnerabilities with CWE-863
CVE-2022-1224 MEDIUM
phpipam < 1.4.6 - Improper Authorization
CVSS 6.5
CVE-2022-1223 MEDIUM
phpipam < 1.4.6 - Incorrect Authorization
CVSS 6.5
CVE-2022-0406 MEDIUM
GitHub janeczku/calibre-web <0.6.16 - Auth Bypass
CVSS 4.3
CVE-2022-1177 MEDIUM
OpenEMR < 6.1.0 - Insufficient Access Control for Patient Reports
CVSS 4.3
CVE-2022-0720 MEDIUM
Amelia WordPress <1.0.47 - Privilege Escalation
CVSS 5.4
CVE-2022-24783 CRITICAL
Deno 1.18.0-1.20.2 - Unauthenticated Privilege Escalation via Permission Check Bypass
CVSS 10.0
CVE-2022-24778 HIGH
imgcrypt < 1.1.4 - Incorrect Authorization via ManifestList Architecture Handling
CVSS 7.5
CVE-2022-26629 CRITICAL
SoroushPlus+ Messenger <1.0.30 - Auth Bypass
CVSS 9.1
CVE-2022-24730 HIGH
Argo CD <2.1.11, 2.2.6, 2.3.0 - Path Traversal
CVSS 7.7
CVE-2022-0981 HIGH
Quarkus < 2.7.1 - Incorrect Authorization via RestEasy Reactive State Leak
CVSS 8.8
CVE-2022-24755 HIGH
Bareos Director <21.1.0, 20.0.6, 19.2.12 - Auth Bypass
CVSS 8.1
CVE-2022-24721 HIGH
CometD <5.0.11,6.0.6,7.0.6 - Info Disclosure
CVSS 8.1
CVE-2022-24128 HIGH
TimescaleDB <2.5.2 - Privilege Escalation
CVSS 8.0
CVE-2022-0860 CRITICAL
cobbler < 3.3.2 - Improper Authorization
CVSS 9.1
CVE-2022-24609 CRITICAL
Luocms v2.0 - Incorrect Access Control via Template Management
CVSS 9.8
CVE-2022-24748 MEDIUM
Shopware <6.4.8.2 - Info Disclosure
CVSS 6.8
CVE-2022-0482 CRITICAL
GitHub alextselegidis/easyappointments <1.4.3 - Info Disclosure
CVSS 9.1
CVE-2022-24714 MEDIUM
Icinga Web 2 < 2.8.6 - Incorrect Authorization via Role Restrictions with Decommissioned Services
CVSS 5.3
CVE-2022-24306 CRITICAL
Zoho ManageEngine SharePoint Manager Plus <4329 - Privilege Escalation
CVSS 9.8
CVE-2022-0829 HIGH
webmin < 1.990 - Improper Authorization
CVSS 8.1
CVE-2022-0824 HIGH
webmin < 1.990 - Improper Access Control to Remote Code Execution
CVSS 8.8
CVE-2022-0577 MEDIUM
scrapy < 2.6.1 - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.5
CVE-2022-0762 MEDIUM
microweber/microweber <1.3 - Info Disclosure
CVSS 5.5
CVE-2022-21706 HIGH
Zulip Server 2.0.0-4.10.0 - Insufficient Access Control via Multi-Use Invitations
CVSS 7.2
CVE-2022-0727 MEDIUM
GitHub chocobozzz/peertube <4.1.0 - Info Disclosure
CVSS 5.4
Details
Vulnerabilities 3,098
Exploit Likelihood High