Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2022-03-25 CVE-2022-24783 Incorrect Authorization vulnerability in Deno
Deno is a runtime for JavaScript and TypeScript.
network
low complexity
deno CWE-863
critical
10.0
2022-03-25 CVE-2021-20290 Incorrect Authorization vulnerability in Theforeman Openscap
An improper authorization handling flaw was found in Foreman.
local
low complexity
theforeman CWE-863
6.1
2022-03-25 CVE-2022-24778 Incorrect Authorization vulnerability in multiple products
The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images.
network
low complexity
linuxfoundation fedoraproject CWE-863
7.5
2022-03-24 CVE-2022-26629 Incorrect Authorization vulnerability in Splus Soroushplus 1.0.30
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.
network
low complexity
splus CWE-863
critical
9.1
2022-03-23 CVE-2022-24730 Incorrect Authorization vulnerability in Argoproj Argo CD
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
network
low complexity
argoproj CWE-863
6.5
2022-03-23 CVE-2022-0981 Incorrect Authorization vulnerability in Quarkus
A flaw was found in Quarkus.
network
low complexity
quarkus CWE-863
8.8
2022-03-15 CVE-2022-24755 Incorrect Authorization vulnerability in Bareos
Bareos is open source software for backup, archiving, and recovery of data for operating systems.
network
low complexity
bareos CWE-863
critical
9.8
2022-03-15 CVE-2022-24721 Incorrect Authorization vulnerability in Cometd
CometD is a scalable comet implementation for web messaging.
network
low complexity
cometd CWE-863
8.1
2022-03-13 CVE-2022-24128 Incorrect Authorization vulnerability in Timescale Timescaledb
Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation.
network
low complexity
timescale CWE-863
8.0
2022-03-10 CVE-2021-41233 Incorrect Authorization vulnerability in Nextcloud Server
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server.
network
low complexity
nextcloud CWE-863
5.3