Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-09-24 CVE-2021-40655 Incorrect Authorization vulnerability in Dlink Dir-605L Firmware 2.01Mt
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT.
network
low complexity
dlink CWE-863
7.5
2021-09-24 CVE-2021-36749 Incorrect Authorization vulnerability in Apache Druid
In the Druid ingestion system, the InputSource is used for reading data from a certain data source.
network
low complexity
apache CWE-863
6.5
2021-09-21 CVE-2020-19551 Incorrect Authorization vulnerability in Wuzhicms
Blacklist bypass issue exists in WUZHI CMS up to and including 4.1.0 in common.func.php, which when uploaded can cause remote code executiong.
network
low complexity
wuzhicms CWE-863
8.8
2021-09-20 CVE-2021-41082 Incorrect Authorization vulnerability in Discourse
Discourse is a platform for community discussion.
network
low complexity
discourse CWE-863
7.5
2021-09-20 CVE-2020-16630 Incorrect Authorization vulnerability in TI products
TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile.
high complexity
ti CWE-863
6.8
2021-09-20 CVE-2019-16651 Incorrect Authorization vulnerability in Virginmedia Super HUB 3 Firmware
An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices.
network
low complexity
virginmedia CWE-863
5.3
2021-09-15 CVE-2021-40639 Incorrect Authorization vulnerability in Jflyfox Jfinal CMS 5.1.0
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
network
low complexity
jflyfox CWE-863
7.5
2021-09-15 CVE-2020-21124 Incorrect Authorization vulnerability in Ureport Project Ureport 2.2.9
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
network
low complexity
ureport-project CWE-863
critical
9.8
2021-09-09 CVE-2021-28911 Incorrect Authorization vulnerability in Bab-Technologie Eibport Firmware 3.8.2/3.8.3
BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g.
network
low complexity
bab-technologie CWE-863
critical
9.8
2021-09-09 CVE-2021-22239 Incorrect Authorization vulnerability in Gitlab
An unauthorized user was able to insert metadata when creating new issue on GitLab CE/EE 14.0 and later.
network
low complexity
gitlab CWE-863
4.3