Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-08-24 CVE-2021-30856 Incorrect Authorization vulnerability in Apple Macos
This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions.
network
low complexity
apple CWE-863
critical
9.1
2021-08-24 CVE-2021-30925 Incorrect Authorization vulnerability in Apple products
The issue was addressed with improved permissions logic.
network
low complexity
apple CWE-863
critical
9.1
2021-08-24 CVE-2021-30972 Incorrect Authorization vulnerability in Apple mac OS X and Macos
This issue was addressed with improved checks.
local
low complexity
apple CWE-863
5.5
2021-08-24 CVE-2021-30975 Incorrect Authorization vulnerability in Apple mac OS X and Macos
This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary.
local
low complexity
apple CWE-863
8.6
2021-08-24 CVE-2021-30987 Incorrect Authorization vulnerability in Apple Macos 12.0/12.0.0/12.0.1
An access issue was addressed with improved access restrictions.
local
low complexity
apple CWE-863
5.5
2021-08-24 CVE-2021-26040 Incorrect Authorization vulnerability in Joomla Joomla! 4.0.0
An issue was discovered in Joomla! 4.0.0.
network
low complexity
joomla CWE-863
critical
9.1
2021-08-23 CVE-2021-22251 Incorrect Authorization vulnerability in Gitlab
Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings
network
low complexity
gitlab CWE-863
4.3
2021-08-23 CVE-2021-22253 Incorrect Authorization vulnerability in Gitlab
Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments to protected environments under specific conditions after the access has been removed
network
low complexity
gitlab CWE-863
5.4
2021-08-19 CVE-2021-37598 Incorrect Authorization vulnerability in Wpcerber WP Cerber
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
network
low complexity
wpcerber CWE-863
5.3
2021-08-19 CVE-2021-39138 Incorrect Authorization vulnerability in Parseplatform Parse-Server
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js.
network
low complexity
parseplatform CWE-863
6.5