Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2019-12-26 CVE-2018-20492 Incorrect Authorization vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1.
network
low complexity
gitlab CWE-863
5.3
2019-12-26 CVE-2019-19681 Incorrect Authorization vulnerability in Artica Pandora FMS 7.0
Pandora FMS 7.x suffers from remote code execution vulnerability.
network
low complexity
artica CWE-863
8.8
2019-12-26 CVE-2019-19984 Incorrect Authorization vulnerability in Icegram Email Subscribers & Newsletters
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
network
low complexity
icegram CWE-863
6.3
2019-12-24 CVE-2017-16778 Incorrect Authorization vulnerability in Fermax Outdoor Panel Firmware
An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a restricted floor/level.
low complexity
fermax CWE-863
4.6
2019-12-20 CVE-2012-6094 Incorrect Authorization vulnerability in multiple products
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
network
low complexity
apple debian CWE-863
critical
9.8
2019-12-19 CVE-2019-11294 Incorrect Authorization vulnerability in Cloudfoundry Cf-Deployment
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
network
low complexity
cloudfoundry CWE-863
4.3
2019-12-18 CVE-2019-8512 Incorrect Authorization vulnerability in Apple Iphone OS
This issue was addressed with improved transparency.
network
low complexity
apple CWE-863
5.7
2019-12-17 CVE-2019-0384 Incorrect Authorization vulnerability in SAP products
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for functionalities that require user identity.
network
low complexity
sap CWE-863
8.8
2019-12-17 CVE-2019-0383 Incorrect Authorization vulnerability in SAP products
Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-FINSERV versions 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-863
8.8
2019-12-05 CVE-2019-7192 Incorrect Authorization vulnerability in Qnap Photo Station
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system.
network
low complexity
qnap CWE-863
critical
9.8