The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,099 vulnerabilities with CWE-863
CVE-2021-24917
HIGH
WPS Hide Login <1.9.1 - Info Disclosure
CVSS 7.5
CVE-2021-4026
MEDIUM
BookStack < 21.11.2 - Improper Access Control
CVSS 4.3
CVE-2021-24842
MEDIUM
WordPress Plugin <1.12 - Info Disclosure
CVSS 5.4
CVE-2021-43560
MEDIUM
Moodle <3.11.3-3.9.10 - Info Disclosure
CVSS 5.3
CVE-2021-22966
HIGH
Concrete CMS <8.5.6 - Privilege Escalation
CVSS 8.8
CVE-2021-39234
MEDIUM
Apache Ozone < 1.2.0 - Authenticated Security Bypass via Block ID Manipulation
CVSS 6.8
CVE-2021-43553
LOW
OSIsoft PI Vision < 2021 - Incorrect Authorization
CVSS 3.1
CVE-2021-24851
MEDIUM
WordPress Insert Pages <3.7.0 - Info Disclosure
CVSS 4.3
CVE-2021-41244
CRITICAL
Grafana 8.0.0-8.2.3 - Unauthorized Role Modification via Fine-Grained Access Control
CVSS 9.1
CVE-2021-3577
HIGH
Motorola-branded Binatone Hubble Cameras - RCE
CVSS 8.8
CVE-2021-1903
MEDIUM
Qualcomm AQT1000 Firmware - Denial of Service via Channel Switch Announcement IE Length Check Bypass
CVSS 5.3
CVE-2021-40504
MEDIUM
SAP NetWeaver Application Server ABAP and ABAP Platform 700-756 - Incorrect Authorization in Template Role
CVSS 4.9
CVE-2021-20119
HIGH
Arris SurfBoard SB8200 Firmware - Incorrect Authorization via Password Change Utility
CVSS 7.1
CVE-2021-42026
MEDIUM
Mendix 8.0.0-8.18.12 and < 9.6.2 - Authenticated Incorrect Authorization
CVSS 4.3
CVE-2021-42025
MEDIUM
Mendix 8.0.0-8.18.12 and <9.6.2 - Authenticated Incorrect Authorization for System.FileDocument Objects
CVSS 6.5
CVE-2021-24788
MEDIUM
Batch Cat WP <0.3 - Privilege Escalation
CVSS 6.5
CVE-2021-24783
MEDIUM
Post Expirator <2.6.0 - Privilege Escalation
CVSS 6.5
CVE-2021-22051
MEDIUM
Spring Cloud Gateway < 2.2.10 and 3.0.0-3.0.5 - Incorrect Authorization
CVSS 6.5
CVE-2021-41230
MEDIUM
Pomerium 0.14.0-0.15.5 - Incorrect Authorization via OIDC Claims
CVSS 5.3
CVE-2021-25506
MEDIUM
Samsung Health <6.19.1.0001 - Info Disclosure
CVSS 4.0
CVE-2021-39904
MEDIUM
GitLab 13.1-14.2.5, 14.3-14.3.3, 14.4 - Improper Access Control in GraphQL API
CVSS 4.3
CVE-2021-39902
MEDIUM
GitLab 13.4-14.2.6 - Incorrect Authorization in Incident Severity Modification
CVSS 4.3
CVE-2021-21693
CRITICAL
Jenkins < 2.303.3 and < 2.319 - Incorrect Authorization in Temporary File Creation
CVSS 9.8
CVE-2021-39341
HIGH
OptinMonster < 2.6.4 - Sensitive Information Disclosure via Insufficient Authorization
CVSS 8.2
CVE-2021-24770
MEDIUM
Stylish Price List WP <6.9.1 - Auth Bypass
CVSS 6.5
Details
Vulnerabilities
3,099
Exploit Likelihood
High