Vulnerabilities > Incorrect Authorization
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-06 | CVE-2021-43781 | Incorrect Authorization vulnerability in Inveniosoftware Invenio-Drafts-Resources Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. | 4.3 |
2021-12-06 | CVE-2021-24917 | Incorrect Authorization vulnerability in Wpserveur WPS Hide Login The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user. | 7.5 |
2021-11-30 | CVE-2021-4026 | Incorrect Authorization vulnerability in Bookstackapp Bookstack bookstack is vulnerable to Improper Access Control | 4.3 |
2021-11-29 | CVE-2021-24842 | Incorrect Authorization vulnerability in Bulk Datetime Change Project Bulk Datetime Change The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts. | 5.4 |
2021-11-19 | CVE-2021-22966 | Incorrect Authorization vulnerability in Concretecms Concrete CMS Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. | 8.8 |
2021-11-19 | CVE-2021-39234 | Incorrect Authorization vulnerability in Apache Ozone In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific request allowing access those blocks, bypassing other security checks like ACL. | 6.8 |
2021-11-17 | CVE-2021-43553 | Incorrect Authorization vulnerability in Osisoft PI Vision 2017/2019/2020 PI Vision could disclose information to a user with insufficient privileges for an AF attribute that is the child of another attribute and is configured as a Limits property. | 4.3 |
2021-11-15 | CVE-2021-41244 | Incorrect Authorization vulnerability in Grafana Grafana is an open-source platform for monitoring and observability. | 7.2 |
2021-11-12 | CVE-2021-3577 | Incorrect Authorization vulnerability in Binatoneglobal products An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device. | 8.8 |
2021-11-10 | CVE-2021-40504 | Incorrect Authorization vulnerability in SAP Netweaver Application Server Abap A certain template role in SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, contains transport authorizations, which exceed expected display only permissions. | 4.9 |