CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,099 vulnerabilities with CWE-863
CVE-2021-24917 HIGH
WPS Hide Login <1.9.1 - Info Disclosure
CVSS 7.5
CVE-2021-4026 MEDIUM
BookStack < 21.11.2 - Improper Access Control
CVSS 4.3
CVE-2021-24842 MEDIUM
WordPress Plugin <1.12 - Info Disclosure
CVSS 5.4
CVE-2021-43560 MEDIUM
Moodle <3.11.3-3.9.10 - Info Disclosure
CVSS 5.3
CVE-2021-22966 HIGH
Concrete CMS <8.5.6 - Privilege Escalation
CVSS 8.8
CVE-2021-39234 MEDIUM
Apache Ozone < 1.2.0 - Authenticated Security Bypass via Block ID Manipulation
CVSS 6.8
CVE-2021-43553 LOW
OSIsoft PI Vision < 2021 - Incorrect Authorization
CVSS 3.1
CVE-2021-24851 MEDIUM
WordPress Insert Pages <3.7.0 - Info Disclosure
CVSS 4.3
CVE-2021-41244 CRITICAL
Grafana 8.0.0-8.2.3 - Unauthorized Role Modification via Fine-Grained Access Control
CVSS 9.1
CVE-2021-3577 HIGH
Motorola-branded Binatone Hubble Cameras - RCE
CVSS 8.8
CVE-2021-1903 MEDIUM
Qualcomm AQT1000 Firmware - Denial of Service via Channel Switch Announcement IE Length Check Bypass
CVSS 5.3
CVE-2021-40504 MEDIUM
SAP NetWeaver Application Server ABAP and ABAP Platform 700-756 - Incorrect Authorization in Template Role
CVSS 4.9
CVE-2021-20119 HIGH
Arris SurfBoard SB8200 Firmware - Incorrect Authorization via Password Change Utility
CVSS 7.1
CVE-2021-42026 MEDIUM
Mendix 8.0.0-8.18.12 and < 9.6.2 - Authenticated Incorrect Authorization
CVSS 4.3
CVE-2021-42025 MEDIUM
Mendix 8.0.0-8.18.12 and <9.6.2 - Authenticated Incorrect Authorization for System.FileDocument Objects
CVSS 6.5
CVE-2021-24788 MEDIUM
Batch Cat WP <0.3 - Privilege Escalation
CVSS 6.5
CVE-2021-24783 MEDIUM
Post Expirator <2.6.0 - Privilege Escalation
CVSS 6.5
CVE-2021-22051 MEDIUM
Spring Cloud Gateway < 2.2.10 and 3.0.0-3.0.5 - Incorrect Authorization
CVSS 6.5
CVE-2021-41230 MEDIUM
Pomerium 0.14.0-0.15.5 - Incorrect Authorization via OIDC Claims
CVSS 5.3
CVE-2021-25506 MEDIUM
Samsung Health <6.19.1.0001 - Info Disclosure
CVSS 4.0
CVE-2021-39904 MEDIUM
GitLab 13.1-14.2.5, 14.3-14.3.3, 14.4 - Improper Access Control in GraphQL API
CVSS 4.3
CVE-2021-39902 MEDIUM
GitLab 13.4-14.2.6 - Incorrect Authorization in Incident Severity Modification
CVSS 4.3
CVE-2021-21693 CRITICAL
Jenkins < 2.303.3 and < 2.319 - Incorrect Authorization in Temporary File Creation
CVSS 9.8
CVE-2021-39341 HIGH
OptinMonster < 2.6.4 - Sensitive Information Disclosure via Insufficient Authorization
CVSS 8.2
CVE-2021-24770 MEDIUM
Stylish Price List WP <6.9.1 - Auth Bypass
CVSS 6.5
Details
Vulnerabilities 3,099
Exploit Likelihood High