Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2024-07-16 CVE-2024-5816 Incorrect Authorization vulnerability in Github Enterprise Server
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token.
network
low complexity
github CWE-863
5.3
2024-07-16 CVE-2024-5817 Incorrect Authorization vulnerability in Github Enterprise Server
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects.
network
low complexity
github CWE-863
6.5
2024-07-09 CVE-2024-39871 Incorrect Authorization vulnerability in Siemens Sinema Remote Connect Server
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1).
network
low complexity
siemens CWE-863
5.4
2024-07-02 CVE-2024-39324 Incorrect Authorization vulnerability in Aimeos Ai-Admin-Graphql
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface.
network
low complexity
aimeos CWE-863
3.8
2024-06-27 CVE-2023-38368 Incorrect Authorization vulnerability in IBM Security Access Manager 10.0.0.0/10.0.7.1
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls.
local
low complexity
ibm CWE-863
5.5
2024-06-27 CVE-2024-4011 Incorrect Authorization vulnerability in Gitlab
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.
network
low complexity
gitlab CWE-863
4.3
2024-06-27 CVE-2024-6323 Incorrect Authorization vulnerability in Gitlab
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.
network
low complexity
gitlab CWE-863
7.5
2024-06-24 CVE-2024-38369 Incorrect Authorization vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-863
4.3
2024-06-21 CVE-2023-38389 Incorrect Authorization vulnerability in Artbees Jupiter X Core
Incorrect Authorization vulnerability in Artbees JupiterX Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JupiterX Core: from n/a through 3.3.8.
network
low complexity
artbees CWE-863
critical
9.8
2024-06-21 CVE-2024-1639 Incorrect Authorization vulnerability in Wpexperts License Manager for Woocommerce
The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.7.
network
low complexity
wpexperts CWE-863
6.5