Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2022-03-15 CVE-2022-24755 Incorrect Authorization vulnerability in Bareos
Bareos is open source software for backup, archiving, and recovery of data for operating systems.
network
bareos CWE-863
6.8
2022-03-15 CVE-2022-24721 Incorrect Authorization vulnerability in Cometd
CometD is a scalable comet implementation for web messaging.
network
low complexity
cometd CWE-863
5.5
2022-03-13 CVE-2022-24128 Incorrect Authorization vulnerability in Timescale Timescaledb
Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation.
network
low complexity
timescale CWE-863
8.0
2022-03-10 CVE-2021-41233 Incorrect Authorization vulnerability in Nextcloud Server
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server.
network
nextcloud CWE-863
4.3
2022-03-10 CVE-2022-24609 Incorrect Authorization vulnerability in Luocms Project Luocms 2.0
Luocms v2.0 is affected by an incorrect access control vulnerability.
network
low complexity
luocms-project CWE-863
critical
10.0
2022-03-09 CVE-2022-24748 Incorrect Authorization vulnerability in Shopware
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework.
network
low complexity
shopware CWE-863
7.5
2022-03-08 CVE-2022-24714 Incorrect Authorization vulnerability in Icinga web 2
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface.
network
low complexity
icinga CWE-863
5.3
2022-03-08 CVE-2021-41241 Incorrect Authorization vulnerability in Nextcloud Server
Nextcloud server is a self hosted system designed to provide cloud style services.
network
low complexity
nextcloud CWE-863
4.3
2022-03-07 CVE-2021-24824 Incorrect Authorization vulnerability in Custom Content Shortcode Project Custom Content Shortcode
The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata.
network
low complexity
custom-content-shortcode-project CWE-863
4.0
2022-03-02 CVE-2021-3658 Incorrect Authorization vulnerability in multiple products
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up.
low complexity
bluez fedoraproject CWE-863
3.3