Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2022-08-01 CVE-2022-31190 Incorrect Authorization vulnerability in Duraspace Dspace
DSpace open source software is a repository application which provides durable access to digital resources.
network
low complexity
duraspace CWE-863
5.3
2022-08-01 CVE-2022-31154 Incorrect Authorization vulnerability in Sourcegraph
Sourcegraph is an opensource code search and navigation engine.
network
low complexity
sourcegraph CWE-863
4.3
2022-08-01 CVE-2022-22326 Incorrect Authorization vulnerability in IBM products
IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks.
local
low complexity
ibm CWE-863
3.3
2022-08-01 CVE-2022-35716 Incorrect Authorization vulnerability in IBM Urbancode Deploy
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 through 7.2.3.0 could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
network
low complexity
ibm CWE-863
6.5
2022-07-26 CVE-2022-1499 Incorrect Authorization vulnerability in Google Chrome
Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
network
low complexity
google CWE-863
6.3
2022-07-25 CVE-2022-1309 Incorrect Authorization vulnerability in Google Chrome
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
network
low complexity
google CWE-863
critical
9.6
2022-07-23 CVE-2022-1132 Incorrect Authorization vulnerability in Google Chrome
Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation restrictions via physical access to the device.
low complexity
google CWE-863
6.1
2022-07-20 CVE-2022-34046 Incorrect Authorization vulnerability in Wavlink Wn533A8 Firmware M33A8.V5030.190716
An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via view-source:http://IP_ADDRESS/sysinit.shtml?r=52300 and searching for [logincheck(user);].
network
low complexity
wavlink CWE-863
7.5
2022-07-17 CVE-2022-26479 Incorrect Authorization vulnerability in Poly Eagleeye Director II Firmware
An issue was discovered in Poly EagleEye Director II before 2.2.2.1.
network
low complexity
poly CWE-863
critical
9.8
2022-07-16 CVE-2022-36126 Incorrect Authorization vulnerability in Inductiveautomation Ignition
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17.
network
low complexity
inductiveautomation CWE-863
7.2