Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-01-11 CVE-2021-0317 Incorrect Authorization vulnerability in Google Android
In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error.
local
low complexity
google CWE-863
7.8
2021-01-11 CVE-2018-8724 Incorrect Authorization vulnerability in K7Computing products
K7Computing Pvt Ltd K7AntiVirus Premium 15.1.0.53 is affected by: Incorrect Access Control.
local
low complexity
k7computing CWE-863
7.8
2021-01-11 CVE-2018-8044 Incorrect Authorization vulnerability in K7Computing products
K7Computing Pvt Ltd K7Antivirus Premium 15.1.0.53 is affected by: Incorrect Access Control.
local
low complexity
k7computing CWE-863
7.8
2021-01-08 CVE-2021-1054 Incorrect Authorization vulnerability in Nvidia GPU Driver
NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action, which may lead to denial of service.
local
low complexity
nvidia CWE-863
5.5
2021-01-01 CVE-2020-35948 Incorrect Authorization vulnerability in Xcloner
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress.
network
low complexity
xcloner CWE-863
8.8
2021-01-01 CVE-2016-20005 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
critical
9.8
2021-01-01 CVE-2016-20004 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
critical
9.8
2021-01-01 CVE-2016-20002 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
critical
9.8
2021-01-01 CVE-2016-20001 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
critical
9.8
2020-12-28 CVE-2020-26029 Incorrect Authorization vulnerability in Zammad
An issue was discovered in Zammad before 3.4.1.
network
low complexity
zammad CWE-863
6.5