Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2019-09-03 CVE-2019-14817 Incorrect Authorization vulnerability in multiple products
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions.
7.8
2019-09-03 CVE-2019-14811 Incorrect Authorization vulnerability in multiple products
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions.
7.8
2019-08-23 CVE-2019-8446 Incorrect Authorization vulnerability in Atlassian Jira Server
The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.
network
low complexity
atlassian CWE-863
5.0
2019-08-14 CVE-2019-1192 Incorrect Authorization vulnerability in Microsoft Edge and Internet Explorer
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'.
network
microsoft CWE-863
4.3
2019-08-09 CVE-2018-20826 Incorrect Authorization vulnerability in Atlassian Jira
The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.
network
low complexity
atlassian CWE-863
4.3
2019-08-07 CVE-2019-1912 Incorrect Authorization vulnerability in Cisco products
A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files.
network
low complexity
cisco CWE-863
6.4
2019-07-26 CVE-2019-13386 Incorrect Authorization vulnerability in Centos-Webpanel Centos web Panel 0.9.8.846
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege.
network
low complexity
centos-webpanel CWE-863
8.8
2019-07-23 CVE-2019-11724 Incorrect Authorization vulnerability in multiple products
Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site.
network
low complexity
mozilla opensuse CWE-863
6.1
2019-07-17 CVE-2019-1010084 Incorrect Authorization vulnerability in Dancer::Plugin::Simplecrud Project Dancer::Plugin::Simplecrud
Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control.
network
low complexity
dancer CWE-863
4.0
2019-07-10 CVE-2019-5220 Incorrect Authorization vulnerability in Huawei products
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones.
local
low complexity
huawei CWE-863
2.1