Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-06-24 CVE-2024-38369 Incorrect Authorization vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-863
4.3
2024-06-11 CVE-2024-31402 Incorrect Authorization vulnerability in Cybozu Garoon
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.
network
low complexity
cybozu CWE-863
4.3
2024-06-10 CVE-2024-27848 Incorrect Authorization vulnerability in Apple Ipados and Macos
This issue was addressed with improved permissions checking.
local
low complexity
apple CWE-863
7.8
2024-06-08 CVE-2024-4146 Incorrect Authorization vulnerability in Lunary 1.2.13
In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they should not have access to.
network
low complexity
lunary CWE-863
critical
9.8
2024-06-06 CVE-2024-37154 Incorrect Authorization vulnerability in Evmos
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network.
network
low complexity
evmos CWE-863
5.3
2024-06-05 CVE-2024-23669 Incorrect Authorization vulnerability in Fortinet Fortiwebmanager
An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.
network
low complexity
fortinet CWE-863
8.8
2024-05-29 CVE-2024-36364 Incorrect Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 improper access control in Pull Requests and Commit status publisher build features was possible
network
low complexity
jetbrains CWE-863
6.5
2024-05-29 CVE-2024-36365 Incorrect Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 a third-party agent could impersonate a cloud agent
network
low complexity
jetbrains CWE-863
8.1
2024-05-27 CVE-2024-36037 Incorrect Authorization vulnerability in Zohocorp Manageengine Adaudit Plus
Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.
local
low complexity
zohocorp CWE-863
5.5
2024-05-23 CVE-2024-5258 Incorrect Authorization vulnerability in Gitlab
An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.
network
low complexity
gitlab CWE-863
4.3