Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-11-09 CVE-2021-20119 Incorrect Authorization vulnerability in Commscope Arris Surfboard Sb8200 Firmware Ab01.02.053.01112320193.0A.Nsh
The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.
high complexity
commscope CWE-863
7.1
2021-11-08 CVE-2021-24783 Incorrect Authorization vulnerability in Publishpress Post Expirator
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.
network
low complexity
publishpress CWE-863
6.5
2021-11-08 CVE-2021-22051 Incorrect Authorization vulnerability in VMWare Spring Cloud Gateway
Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services.
network
low complexity
vmware CWE-863
6.5
2021-11-05 CVE-2021-25506 Incorrect Authorization vulnerability in Samsung Health
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
local
low complexity
samsung CWE-863
5.5
2021-11-05 CVE-2021-39904 Incorrect Authorization vulnerability in Gitlab
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request
network
low complexity
gitlab CWE-863
4.3
2021-11-04 CVE-2021-39902 Incorrect Authorization vulnerability in Gitlab
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.
network
low complexity
gitlab CWE-863
4.3
2021-11-04 CVE-2021-21693 Incorrect Authorization vulnerability in Jenkins
When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
network
low complexity
jenkins CWE-863
critical
9.8
2021-11-01 CVE-2021-24717 Incorrect Authorization vulnerability in Automatorwp
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.
network
low complexity
automatorwp CWE-863
8.8
2021-10-29 CVE-2021-41189 Incorrect Authorization vulnerability in Duraspace Dspace 7.0
DSpace is an open source turnkey repository application.
network
low complexity
duraspace CWE-863
7.2
2021-10-14 CVE-2021-38345 Incorrect Authorization vulnerability in Brizy Brizy-Page Builder
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor.
network
low complexity
brizy CWE-863
6.5