Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2023-02-11 CVE-2023-25559 Incorrect Authorization vulnerability in Datahub Project Datahub
DataHub is an open-source metadata platform.
network
low complexity
datahub-project CWE-863
8.1
2023-02-09 CVE-2023-21422 Incorrect Authorization vulnerability in Samsung Android 11.0/12.0
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
local
low complexity
samsung CWE-863
5.5
2023-02-09 CVE-2023-21423 Incorrect Authorization vulnerability in Samsung Android 12.0/13.0
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.
local
low complexity
samsung CWE-863
5.5
2023-02-09 CVE-2023-21424 Incorrect Authorization vulnerability in Samsung Android 11.0/12.0
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.
local
low complexity
samsung CWE-863
3.3
2023-02-07 CVE-2022-45544 Incorrect Authorization vulnerability in Schlix CMS 2.2.72
Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter.
network
low complexity
schlix CWE-863
8.8
2023-02-07 CVE-2023-23696 Incorrect Authorization vulnerability in Dell Command | Intel Vpro OUT of Band
Dell Command Intel vPro Out of Band, versions prior to 4.3.1, contain an Improper Authorization vulnerability.
local
low complexity
dell CWE-863
7.8
2023-02-03 CVE-2023-24029 Incorrect Authorization vulnerability in Progress WS FTP Server
In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to insufficient authorization controls applied on user modification workflows.
network
low complexity
progress CWE-863
7.2
2023-02-01 CVE-2023-23751 Incorrect Authorization vulnerability in Joomla Joomla!
An issue was discovered in Joomla! 4.0.0 through 4.2.4.
network
low complexity
joomla CWE-863
4.3
2023-02-01 CVE-2022-47002 Incorrect Authorization vulnerability in Masacms
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.
network
low complexity
masacms CWE-863
critical
9.8
2023-02-01 CVE-2023-23924 Incorrect Authorization vulnerability in Dompdf Project Dompdf 2.0.1
Dompdf is an HTML to PDF converter.
network
low complexity
dompdf-project CWE-863
critical
9.8