The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,104 vulnerabilities with CWE-863
CVE-2021-40639
HIGH
Jfinal CMS 5.1.0 - Incorrect Authorization via /classes/conf/db.properties
CVSS 7.5
CVE-2021-39206
HIGH
Envoy < 1.16.5 - Incorrect Authorization
CVSS 8.6
CVE-2021-28911
CRITICAL
BAB TECHNOLOGIE eibPort V3 < 3.9.1 - Unauthenticated Sensitive Data Exposure in /tmp Path
CVSS 9.8
CVE-2021-22239
MEDIUM
GitLab 14.0.0-14.0.7 - Unauthenticated Metadata Injection in Issue Creation
CVSS 5.0
CVE-2021-28567
MEDIUM
Magento < 2.4.2 - Authenticated Improper Authorization in Customers Module
CVSS 6.5
CVE-2021-35526
MEDIUM
Hitachi ABB Power Grids System Data Manager - Info Disclosure
CVSS 6.3
CVE-2021-1854
MEDIUM
iPadOS < 14.5 - Unauthenticated Call Termination Bypass
CVSS 4.3
CVE-2021-35949
MEDIUM
ownCloud Server <10.8.0 - Auth Bypass
CVSS 5.3
CVE-2021-38312
HIGH
Gutenberg Template Library & Redux Framework <= 4.2.11 - Auth Bypass
CVSS 7.1
CVE-2021-39119
MEDIUM
Atlassian Jira Server and Data Center < 8.19.0 - Broken Access Control in Issue Notification Feature
CVSS 5.3
CVE-2021-36039
MEDIUM
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
CVSS 6.5
CVE-2021-39164
LOW
Matrix Synapse < 1.41.1 - Unauthenticated Exposure of Room Membership via History Visibility
CVSS 3.1
CVE-2021-39163
LOW
Matrix Synapse < 1.41.1 - Unauthenticated Exposure of Sensitive Room Information via Group Endpoints
CVSS 3.1
CVE-2021-34434
MEDIUM
Eclipse Mosquitto 2.0-2.0.11 - Improper Authorization in Dynamic Security Plugin
CVSS 5.3
CVE-2021-28696
MEDIUM
Xen - Incorrect Authorization in IOMMU Page Mapping
CVSS 6.8
CVE-2021-22256
MEDIUM
GitLab 12.6.0-13.12.8 - Unauthenticated Issue Creation for Sentry Errors
CVSS 5.4
CVE-2021-22247
MEDIUM
GitLab 13.0.0-13.12.9 - Incorrect Authorization for CI/CD Analytics
CVSS 4.3
CVE-2021-22243
MEDIUM
GitLab 7.10.0-13.12.8 - Incorrect Authorization via Invite URL
CVSS 5.0
CVE-2021-22236
MEDIUM
GitLab 14.1.0-14.1.1 - Incorrect Authorization via OAuth Client ID Handling
CVSS 5.5
CVE-2021-39156
HIGH
Istio < 1.9.8 - Authorization Bypass via URI Fragment
CVSS 8.1
CVE-2021-39155
HIGH
Istio < 1.9.8 - Authorization Policy Bypass via Case-Sensitive Hostname Comparison
CVSS 8.3
CVE-2021-32779
HIGH
Envoy 1.16.0-1.16.4 - Privilege Escalation via URI Fragment Mishandling
CVSS 8.6
CVE-2021-32777
HIGH
Envoy 1.16.0-1.16.4 - Authorization Bypass via Ext-Authz Header Merging
CVSS 8.6
CVE-2021-30987
MEDIUM
macOS Monterey <12.1 - Info Disclosure
CVSS 5.5
CVE-2021-30975
HIGH
macOS < 10.15.7 and 11.0-11.6.2 - Gatekeeper Bypass via Malicious OSAX Scripting Addition
CVSS 8.6
Details
Vulnerabilities
3,104
Exploit Likelihood
High