Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-01-28 CVE-2020-1725 Incorrect Authorization vulnerability in Redhat Keycloak
A flaw was found in keycloak before version 13.0.0.
network
low complexity
redhat CWE-863
5.5
2021-01-26 CVE-2021-26026 Incorrect Authorization vulnerability in Acdsee Photo Studio 2021 14.0
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!JPEGTransW+0x000000000000c7f4 via a crafted BMP image.
network
acdsee CWE-863
6.8
2021-01-26 CVE-2021-26025 Incorrect Authorization vulnerability in Acdsee Photo Studio 2021 14.0
PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDStd!zlibVersion+0x0000000000004e5e via a crafted BMP image.
network
acdsee CWE-863
6.8
2021-01-26 CVE-2020-9492 Incorrect Authorization vulnerability in multiple products
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.
network
low complexity
apache oracle CWE-863
8.8
2021-01-26 CVE-2020-23449 Incorrect Authorization vulnerability in Newbee-Mall Project Newbee-Mall
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java.
network
low complexity
newbee-mall-project CWE-863
5.0
2021-01-20 CVE-2021-1305 Incorrect Authorization vulnerability in Cisco products
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system, gain access to sensitive information, and view information that they are not authorized to access.
network
low complexity
cisco CWE-863
4.3
2021-01-20 CVE-2021-1270 Incorrect Authorization vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization.
network
low complexity
cisco CWE-863
6.5
2021-01-20 CVE-2021-1269 Incorrect Authorization vulnerability in Cisco Data Center Network Manager
Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization.
network
low complexity
cisco CWE-863
6.3
2021-01-19 CVE-2020-8581 Incorrect Authorization vulnerability in Netapp Clustered Data Ontap
Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.
network
netapp CWE-863
3.5
2021-01-13 CVE-2021-21013 Incorrect Authorization vulnerability in Adobe Magento
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module.
network
low complexity
adobe CWE-863
5.5