Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2023-11-20 CVE-2023-5799 Incorrect Authorization vulnerability in Thimpress WP Hotel Booking
The WP Hotel Booking WordPress plugin before 2.0.8 does not have proper authorisation when deleting a package, allowing Contributor and above roles to delete posts that do no belong to them
network
low complexity
thimpress CWE-863
5.4
2023-11-20 CVE-2023-48218 Incorrect Authorization vulnerability in Strapi Protected Populate
The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information.
network
low complexity
strapi CWE-863
5.3
2023-11-14 CVE-2022-40681 Incorrect Authorization vulnerability in Fortinet Forticlient
A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to cause denial of service via sending a crafted request to a specific named pipe.
local
low complexity
fortinet CWE-863
7.1
2023-11-14 CVE-2023-31403 Incorrect Authorization vulnerability in SAP Business ONE 10.0
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder.
low complexity
sap CWE-863
8.0
2023-11-12 CVE-2023-47037 Incorrect Authorization vulnerability in Apache Airflow
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then.  Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes.
network
low complexity
apache CWE-863
4.3
2023-11-07 CVE-2023-46244 Incorrect Authorization vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-863
8.8
2023-11-07 CVE-2023-42541 Incorrect Authorization vulnerability in Samsung Push Service
Improper authorization in PushClientProvider of Samsung Push Service prior to version 3.4.10 allows attacker to access unique id.
network
low complexity
samsung CWE-863
5.3
2023-11-06 CVE-2023-5352 Incorrect Authorization vulnerability in Getawesomesupport Awesome Support
The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.
network
low complexity
getawesomesupport CWE-863
4.3
2023-11-01 CVE-2023-20048 Incorrect Authorization vulnerability in Cisco Firepower Management Center
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software.
network
low complexity
cisco CWE-863
critical
9.9
2023-10-31 CVE-2023-22518 Incorrect Authorization vulnerability in Atlassian Confluence Data Center
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability.
network
low complexity
atlassian CWE-863
critical
9.8