Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-10-10 CVE-2024-45131 Incorrect Authorization vulnerability in Adobe Commerce and Magento
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass.
network
low complexity
adobe CWE-863
5.4
2024-10-10 CVE-2024-45132 Incorrect Authorization vulnerability in Adobe Commerce and Magento
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation.
network
low complexity
adobe CWE-863
6.5
2024-10-10 CVE-2024-9623 Incorrect Authorization vulnerability in Gitlab
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository.
network
low complexity
gitlab CWE-863
6.5
2024-10-07 CVE-2024-38425 Incorrect Authorization vulnerability in Qualcomm products
Information disclosure while sending implicit broadcast containing APP launch information.
local
low complexity
qualcomm CWE-863
6.1
2024-10-04 CVE-2024-47183 Incorrect Authorization vulnerability in Parseplatform Parse Server
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
network
low complexity
parseplatform CWE-863
8.1
2024-09-30 CVE-2024-47172 Incorrect Authorization vulnerability in Cvat Computer Vision Annotation Tool
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision.
network
low complexity
cvat CWE-863
5.4
2024-09-26 CVE-2024-8974 Incorrect Authorization vulnerability in Gitlab
Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."
network
low complexity
gitlab CWE-863
4.3
2024-09-26 CVE-2024-7108 Incorrect Authorization vulnerability in Nationalkeep Cybermath 1.4
Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CyberMath: before CYBM.240816253.
network
low complexity
nationalkeep CWE-863
critical
9.8
2024-09-25 CVE-2024-20510 Incorrect Authorization vulnerability in Cisco IOS XE
A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication. This vulnerability is due to a logic error when activating the pre-authentication ACL that is received from the authentication, authorization, and accounting (AAA) server.
low complexity
cisco CWE-863
critical
9.3
2024-09-25 CVE-2024-47078 Meshtastic is an open source, off-grid, decentralized, mesh network.
network
low complexity
CWE-863
critical
9.8