Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-10-01 CVE-2020-15664 Incorrect Authorization vulnerability in Mozilla Firefox and Firefox ESR
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension.
network
low complexity
mozilla CWE-863
6.5
2020-09-30 CVE-2020-13322 Incorrect Authorization vulnerability in Gitlab
A vulnerability was discovered in GitLab versions after 12.9.
network
low complexity
gitlab CWE-863
7.2
2020-09-27 CVE-2020-26121 Incorrect Authorization vulnerability in multiple products
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4.
network
low complexity
mediawiki fedoraproject CWE-863
7.5
2020-09-27 CVE-2020-25869 Incorrect Authorization vulnerability in multiple products
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4.
network
low complexity
mediawiki fedoraproject CWE-863
7.5
2020-09-24 CVE-2020-3477 Incorrect Authorization vulnerability in Cisco IOS 16.3.11
A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem.
local
low complexity
cisco CWE-863
5.5
2020-09-24 CVE-2020-3474 Incorrect Authorization vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-863
8.1
2020-09-24 CVE-2020-3404 Incorrect Authorization vulnerability in Cisco IOS XE 16.11.1
A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS) with root privileges.
local
low complexity
cisco CWE-863
7.8
2020-09-22 CVE-2020-4621 Incorrect Authorization vulnerability in IBM Data Risk Manager
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization checks.
network
low complexity
ibm CWE-863
8.8
2020-09-16 CVE-2020-2258 Incorrect Authorization vulnerability in Jenkins Health Advisor BY Cloudbees
Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint.
network
low complexity
jenkins CWE-863
4.3
2020-09-14 CVE-2020-15590 Incorrect Authorization vulnerability in Privateinternetaccess Private Internet Access VPN Client 1.5.0
A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic.
network
low complexity
privateinternetaccess CWE-863
7.5