CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,736)
page 122 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-9902 | Med | 0.34 | 6.3 | 0.00 | Nov 6, 2024 | A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home… | ||
| CVE-2024-5816 | Med | 0.34 | 5.3 | 0.01 | Jul 16, 2024 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not… | ||
| CVE-2024-37154 | Med | 0.34 | 5.3 | 0.00 | Jun 6, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects employees and grantees who have funds managed via `ClawbackVestingAccount`. This affects 18.1.0 and earlier. | ||
| CVE-2024-21120 | Med | 0.34 | 5.3 | 0.00 | Apr 16, 2024 | Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where… | ||
| CVE-2024-27288 | Med | 0.34 | 6.3 | 0.00 | Mar 6, 2024 | 1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are no known workarounds. | ||
| CVE-2023-6963 | Med | 0.34 | 5.3 | 0.01 | Feb 5, 2024 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to bypass the Captcha Verification of the Contact Form block by omitting 'g-recaptcha-response' from… | ||
| CVE-2023-44401 | Med | 0.34 | 5.3 | 0.00 | Jan 23, 2024 | The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is… | ||
| CVE-2023-50705 | Med | 0.34 | 5.3 | 0.01 | Dec 20, 2023 | An attacker could create malicious requests to obtain sensitive information about the web server. | ||
| CVE-2023-3379 | Med | 0.34 | 5.3 | 0.00 | Nov 20, 2023 | Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges. | ||
| CVE-2023-46754 | Med | 0.34 | 5.3 | 0.00 | Oct 26, 2023 | The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values. | ||
| CVE-2023-37367 | Med | 0.34 | 5.3 | 0.00 | Sep 8, 2023 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. In the NAS… | ||
| CVE-2023-4227 | Med | 0.34 | 5.3 | 0.00 | Aug 24, 2023 | A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security breaches, data theft, and unauthorized… | ||
| CVE-2023-38958 | Med | 0.34 | 5.3 | 0.00 | Aug 3, 2023 | An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request. | ||
| CVE-2021-30205 | Med | 0.34 | 5.3 | 0.01 | Jun 27, 2023 | Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames. | ||
| CVE-2022-48495 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cause foreground app information to be obtained. | ||
| CVE-2022-48488 | Med | 0.34 | 5.3 | 0.00 | Jun 19, 2023 | Vulnerability of bypassing the default desktop security controls.Successful exploitation of this vulnerability may cause unauthorized modifications to the desktop. | ||
| CVE-2023-24505 | Med | 0.34 | 5.3 | 0.01 | May 8, 2023 | Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request. | ||
| CVE-2023-25415 | Med | 0.34 | 5.3 | 0.01 | Apr 11, 2023 | Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration. | ||
| CVE-2022-4167 | Med | 0.34 | 5.3 | 0.01 | Jan 12, 2023 | Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them. | ||
| CVE-2022-3188 | Med | 0.34 | 5.3 | 0.01 | Dec 21, 2022 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authentication and download the history file from the device; the history file includes the latest actions completed by specific users. … |
- risk 0.34cvss 6.3epss 0.00
A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home…
- risk 0.34cvss 5.3epss 0.01
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not…
- risk 0.34cvss 5.3epss 0.00
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects employees and grantees who have funds managed via `ClawbackVestingAccount`. This affects 18.1.0 and earlier.
- risk 0.34cvss 5.3epss 0.00
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…
- risk 0.34cvss 6.3epss 0.00
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are no known workarounds.
- risk 0.34cvss 5.3epss 0.01
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to bypass the Captcha Verification of the Contact Form block by omitting 'g-recaptcha-response' from…
- risk 0.34cvss 5.3epss 0.00
The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is…
- risk 0.34cvss 5.3epss 0.01
An attacker could create malicious requests to obtain sensitive information about the web server.
- risk 0.34cvss 5.3epss 0.00
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
- risk 0.34cvss 5.3epss 0.00
The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values.
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. In the NAS…
- risk 0.34cvss 5.3epss 0.00
A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which can be exploited by malicious actors to potentially gain unauthorized access to the product. This could lead to security breaches, data theft, and unauthorized…
- risk 0.34cvss 5.3epss 0.00
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.
- risk 0.34cvss 5.3epss 0.01
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cause foreground app information to be obtained.
- risk 0.34cvss 5.3epss 0.00
Vulnerability of bypassing the default desktop security controls.Successful exploitation of this vulnerability may cause unauthorized modifications to the desktop.
- risk 0.34cvss 5.3epss 0.01
Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.
- risk 0.34cvss 5.3epss 0.01
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Event Notification configuration.
- risk 0.34cvss 5.3epss 0.01
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.
- risk 0.34cvss 5.3epss 0.01
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PHP index pages without authentication and download the history file from the device; the history file includes the latest actions completed by specific users. …