Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2018-10-09 CVE-2018-17857 Incorrect Authorization vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.8.13.
network
low complexity
joomla CWE-863
4.3
2018-10-08 CVE-2018-1000805 Incorrect Authorization vulnerability in multiple products
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE.
network
low complexity
paramiko redhat debian canonical CWE-863
8.8
2018-10-05 CVE-2018-15405 Incorrect Authorization vulnerability in Cisco UCS Director 2.1(0.0)/6.6(1.0)
A vulnerability in the web interface for specific feature sets of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to access sensitive information.
network
low complexity
cisco CWE-863
6.5
2018-10-05 CVE-2018-0460 Incorrect Authorization vulnerability in Cisco Network Functions Virtualization Infrastructure
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system.
network
low complexity
cisco CWE-863
6.5
2018-10-05 CVE-2018-0459 Incorrect Authorization vulnerability in Cisco Network Functions Virtualization Infrastructure
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down.
network
low complexity
cisco CWE-863
6.5
2018-10-02 CVE-2018-9492 Incorrect Authorization vulnerability in Google Android 8.0/8.1/9.0
In checkGrantUriPermissionLocked of ActivityManagerService.java, there is a possible permissions bypass.
local
low complexity
google CWE-863
7.8
2018-09-28 CVE-2018-1250 Incorrect Authorization vulnerability in Dell EMC Unity Firmware and EMC Unityvsa
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains an Authorization Bypass vulnerability.
network
low complexity
dell CWE-863
6.5
2018-09-21 CVE-2018-16597 Incorrect Authorization vulnerability in multiple products
An issue was discovered in the Linux kernel before 4.8.
local
low complexity
linux netapp opensuse CWE-863
5.5
2018-09-18 CVE-2018-7929 Incorrect Authorization vulnerability in Huawei Mate RS Firmware 9.1.0.321(C786E320R1P1T8)
Huawei Mate RS smartphones with the versions before NEO-AL00D 8.1.0.167(C786) have a lock-screen bypass vulnerability.
low complexity
huawei CWE-863
6.8
2018-08-23 CVE-2018-1999047 Incorrect Authorization vulnerability in Jenkins
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.
network
low complexity
jenkins CWE-863
6.5