The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,099 vulnerabilities with CWE-863
CVE-2021-32986
CRITICAL
Automation Direct CLICK PLC CPU <3.00 - Privilege Escalation
CVSS 9.8
CVE-2021-32960
HIGH
Rockwellautomation Factorytalk Services Platform < 6.11.00 - Incorrect Authorization
CVSS 8.5
CVE-2021-28504
HIGH
Arista EOS 4.26-4.26.4m - Improper Access Control via TCAM Profile VXLAN Protocol Rule
CVSS 7.5
CVE-2021-37517
HIGH
Dolibarr ERP/CRM < 14.0.1 - Denial of Service via Forgot-Password Email Handling
CVSS 7.5
CVE-2021-3456
HIGH
Foreman smart_proxy_salt < 2.1.5 - Authenticated Incorrect Authorization
CVSS 7.1
CVE-2021-39790
HIGH
Android 12L - Unauthenticated Local Privilege Escalation via Visual Voicemail Settings Manipulation
CVSS 7.8
CVE-2021-39789
HIGH
Android 12L - Incorrect Authorization in Telecom
CVSS 7.8
CVE-2021-39876
MEDIUM
GitLab 11.3-14.1.7 - Unauthenticated Information Disclosure via Assignee Auto-Complete Endpoint
CVSS 4.3
CVE-2021-20290
MEDIUM
Foreman OpenSCAP < 0.9.1 - Authenticated Incorrect Authorization and Denial of Service
CVSS 6.1
CVE-2021-24905
HIGH
Advanced Contact form 7 DB <1.8.7 - CSRF
CVSS 8.0
CVE-2021-41233
MEDIUM
Nextcloud <22.2.1 - Info Disclosure
CVSS 6.5
CVE-2021-41241
MEDIUM
Nextcloud Server < 20.0.14 - Missing Authorization in Groupfolders Subfolder Access
CVSS 4.3
CVE-2021-24824
MEDIUM
Custom Content Shortcode <4.0.1 - Info Disclosure
CVSS 4.3
CVE-2021-3658
MEDIUM
bluez < 5.61 - Incorrect Authorization via Discoverable Status Persistence
CVSS 6.5
CVE-2021-3560
HIGH
KEV
polkit < 0.119 - Unauthenticated Privilege Escalation via D-Bus Request
CVSS 7.8
CVE-2021-22042
HIGH
VMware Cloud Foundation 4.0-4.3 - Unauthorized Access via VMX Authorization Ticket
CVSS 7.8
CVE-2021-39943
MEDIUM
GitLab 14.1.0-14.3.5, 14.4.0-14.4.3, 14.5.0-14.5.1 - Incorrect Authorization in External Status Check API
CVSS 4.3
CVE-2021-24947
MEDIUM
RVM WordPress <6.4.2 - Info Disclosure
CVSS 6.5
CVE-2021-29394
MEDIUM
Northstar Club Management 6.3 - Authenticated Account Hijacking via UserID Parameter
CVSS 6.5
CVE-2021-41571
MEDIUM
Apache Pulsar < 2.6.4 - Incorrect Authorization in Admin API get-message-by-id
CVSS 6.5
CVE-2021-25097
MEDIUM
LabTools < 1.0 - Authenticated Cross-Site Request Forgery in Publication Deletion
CVSS 6.5
CVE-2021-46561
HIGH
CVE Services API 1.1.1 - Incorrect Authorization via User Account Transfer
CVSS 7.2
CVE-2021-4133
HIGH
Keycloak 12.0.0-15.1.0 - Incorrect Authorization via Administrative REST API
CVSS 8.8
CVE-2021-24733
MEDIUM
WP Post Page Clone <1.2 - Info Disclosure
CVSS 4.3
CVE-2021-37864
LOW
Mattermost < 6.1 - Authenticated Improper Access Control via Archived Channel API
CVSS 2.6
Details
Vulnerabilities
3,099
Exploit Likelihood
High