Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-11-09 CVE-2021-42026 Incorrect Authorization vulnerability in Mendix
A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2).
network
low complexity
mendix CWE-863
4.3
2021-11-08 CVE-2021-24783 Incorrect Authorization vulnerability in Publishpress Post Expirator
The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow users with a role as low as Contributor to schedule deletion of arbitrary posts.
network
low complexity
publishpress CWE-863
6.5
2021-11-08 CVE-2021-22051 Incorrect Authorization vulnerability in VMWare Spring Cloud Gateway
Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services.
network
low complexity
vmware CWE-863
6.5
2021-11-05 CVE-2021-41230 Incorrect Authorization vulnerability in Pomerium
Pomerium is an open source identity-aware access proxy.
network
low complexity
pomerium CWE-863
8.8
2021-11-05 CVE-2021-25506 Incorrect Authorization vulnerability in Samsung Health
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
local
low complexity
samsung CWE-863
5.5
2021-11-05 CVE-2021-39904 Incorrect Authorization vulnerability in Gitlab
An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions and apply suggestions after a project owner has locked the Merge Request
network
low complexity
gitlab CWE-863
4.3
2021-11-04 CVE-2021-39902 Incorrect Authorization vulnerability in Gitlab
Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.
network
low complexity
gitlab CWE-863
4.3
2021-11-04 CVE-2021-21693 Incorrect Authorization vulnerability in Jenkins
When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
network
low complexity
jenkins CWE-863
critical
9.8
2021-11-01 CVE-2021-39341 Incorrect Authorization vulnerability in Optinmonster
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed.
network
low complexity
optinmonster CWE-863
8.2
2021-11-01 CVE-2021-24717 Incorrect Authorization vulnerability in Automatorwp
The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.
network
low complexity
automatorwp CWE-863
8.8