Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-12-23 CVE-2021-23175 Incorrect Authorization vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream.
local
low complexity
nvidia CWE-863
8.2
2021-12-23 CVE-2021-38016 Incorrect Authorization vulnerability in multiple products
Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-863
8.8
2021-12-23 CVE-2021-38017 Incorrect Authorization vulnerability in multiple products
Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google fedoraproject debian CWE-863
8.8
2021-12-17 CVE-2021-23803 Incorrect Authorization vulnerability in Nette Latte
This affects the package latte/latte before 2.10.6.
network
low complexity
nette CWE-863
critical
9.8
2021-12-16 CVE-2021-45102 Incorrect Authorization vulnerability in Wisc Htcondor
An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2.
network
low complexity
wisc CWE-863
8.8
2021-12-15 CVE-2021-0649 Incorrect Authorization vulnerability in Google Android 11.0
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass.
local
low complexity
google CWE-863
7.8
2021-12-13 CVE-2021-39918 Incorrect Authorization vulnerability in Gitlab
Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.
network
low complexity
gitlab CWE-863
4.3
2021-12-13 CVE-2021-39930 Incorrect Authorization vulnerability in Gitlab
Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates
network
low complexity
gitlab CWE-863
4.3
2021-12-13 CVE-2021-39936 Incorrect Authorization vulnerability in Gitlab
Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.
network
low complexity
gitlab CWE-863
4.3
2021-12-13 CVE-2021-39945 Incorrect Authorization vulnerability in Gitlab
Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked
network
low complexity
gitlab CWE-863
2.7