Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-10-07 CVE-2024-38425 Incorrect Authorization vulnerability in Qualcomm products
Information disclosure while sending implicit broadcast containing APP launch information.
local
low complexity
qualcomm CWE-863
6.1
2024-10-04 CVE-2024-47183 Incorrect Authorization vulnerability in Parseplatform Parse Server
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
network
low complexity
parseplatform CWE-863
8.1
2024-09-30 CVE-2024-47172 Incorrect Authorization vulnerability in Cvat Computer Vision Annotation Tool
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision.
network
low complexity
cvat CWE-863
5.4
2024-09-26 CVE-2024-8974 Incorrect Authorization vulnerability in Gitlab
Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."
network
low complexity
gitlab CWE-863
4.3
2024-09-26 CVE-2024-7108 Incorrect Authorization vulnerability in Nationalkeep Cybermath 1.4
Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CyberMath: before CYBM.240816253.
network
low complexity
nationalkeep CWE-863
critical
9.8
2024-09-25 CVE-2024-20510 Incorrect Authorization vulnerability in Cisco IOS XE
A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication. This vulnerability is due to a logic error when activating the pre-authentication ACL that is received from the authentication, authorization, and accounting (AAA) server.
low complexity
cisco CWE-863
critical
9.3
2024-09-25 CVE-2024-47078 Incorrect Authorization vulnerability in Meshtastic Firmware
Meshtastic is an open source, off-grid, decentralized, mesh network.
network
low complexity
meshtastic CWE-863
critical
9.8
2024-09-25 CVE-2024-6512 Incorrect Authorization vulnerability in Devolutions Server
Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.
network
low complexity
devolutions CWE-863
6.5
2024-09-25 CVE-2024-6592 Incorrect Authorization vulnerability in Watchguard Authentication Gateway and Single Sign-On Client
Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 12.10.2; Windows Single Sign-On Client: through 12.7; MacOS Single Sign-On Client: through 12.5.4.
network
low complexity
watchguard CWE-863
critical
9.1
2024-09-25 CVE-2024-6593 Incorrect Authorization vulnerability in Watchguard Authentication Gateway
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. This issue affects Authentication Gateway: through 12.10.2.
network
low complexity
watchguard CWE-863
critical
9.1