Vulnerabilities > Improper Authorization

DATE CVE VULNERABILITY TITLE RISK
2023-08-25 CVE-2023-32678 Improper Authorization vulnerability in Zulip Server
Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat.
network
low complexity
zulip CWE-285
6.5
2023-08-08 CVE-2023-37491 Improper Authorization vulnerability in SAP Message Server
The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, RNL64UC 7.22, RNL64UC 7.22EXT, RNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, can be bypassed in certain conditions, which may enable an authenticated malicious user to enter the network of the SAP systems served by the attacked SAP Message server.
network
low complexity
sap CWE-285
8.8
2023-07-21 CVE-2023-3805 Improper Authorization vulnerability in Four-Faith Video Surveillance Management System 2016/2017
A vulnerability, which was classified as critical, has been found in Xiamen Four Letter Video Surveillance Management System up to 20230712.
network
low complexity
four-faith CWE-285
critical
9.8
2023-07-03 CVE-2023-36611 Improper Authorization vulnerability in Ovarro products
The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege.
network
low complexity
ovarro CWE-285
6.5
2023-06-23 CVE-2023-34460 Improper Authorization vulnerability in Tauri 1.4.0
Tauri is a framework for building binaries for all major desktop platforms.
network
low complexity
tauri CWE-285
critical
9.8
2023-05-28 CVE-2023-2950 Improper Authorization vulnerability in Open-Emr Openemr
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
network
low complexity
open-emr CWE-285
8.1
2023-04-27 CVE-2023-2345 Improper Authorization vulnerability in Oretnom23 Service Provider Management System 1.0
A vulnerability was found in SourceCodester Service Provider Management System 1.0 and classified as critical.
network
low complexity
oretnom23 CWE-285
critical
9.8
2023-04-21 CVE-2023-2227 Improper Authorization vulnerability in Modoboa 2.0.4
Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.
network
low complexity
modoboa CWE-285
critical
9.1
2023-03-05 CVE-2023-0734 Improper Authorization vulnerability in Wallabag
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.
network
low complexity
wallabag CWE-285
5.3
2023-02-03 CVE-2022-24894 Improper Authorization vulnerability in Sensiolabs Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs CWE-285
8.8