Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2023-03-08 CVE-2022-4315 Incorrect Authorization vulnerability in Gitlab Dynamic Application Security Testing Analyzer
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
network
low complexity
gitlab CWE-863
6.5
2023-03-08 CVE-2023-22891 Incorrect Authorization vulnerability in Smartbear Zephyr Enterprise
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.
network
low complexity
smartbear CWE-863
8.1
2023-03-08 CVE-2023-27486 Incorrect Authorization vulnerability in Xcat Project Xcat
xCAT is a toolkit for deployment and administration of computer clusters.
network
low complexity
xcat-project CWE-863
8.8
2023-03-07 CVE-2023-27485 Incorrect Authorization vulnerability in THM Feedbacksystem
thmmniii/fbs-core is an open source feedback system for students.
network
low complexity
thm CWE-863
4.3
2023-03-03 CVE-2023-1164 Incorrect Authorization vulnerability in Kylinos Kylin OS
A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical.
local
low complexity
kylinos CWE-863
7.8
2023-03-02 CVE-2023-26056 Incorrect Authorization vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-863
5.4
2023-03-01 CVE-2023-0952 Incorrect Authorization vulnerability in Devolutions Server
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.
network
low complexity
devolutions CWE-863
6.5
2023-02-28 CVE-2023-25575 Incorrect Authorization vulnerability in Api-Platform Core
API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs.
network
low complexity
api-platform CWE-863
6.5
2023-02-23 CVE-2023-23918 Incorrect Authorization vulnerability in Nodejs Node.Js
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require().
network
low complexity
nodejs CWE-863
7.5
2023-02-17 CVE-2023-23064 Incorrect Authorization vulnerability in Totolink A720R Firmware 4.1.5Cu.532B20210610
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.
network
low complexity
totolink CWE-863
critical
9.8