Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-09-30 CVE-2020-13322 Incorrect Authorization vulnerability in Gitlab
A vulnerability was discovered in GitLab versions after 12.9.
network
low complexity
gitlab CWE-863
7.2
2020-09-27 CVE-2020-26121 Incorrect Authorization vulnerability in multiple products
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4.
network
low complexity
mediawiki fedoraproject CWE-863
7.5
2020-09-27 CVE-2020-25869 Incorrect Authorization vulnerability in multiple products
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4.
network
low complexity
mediawiki fedoraproject CWE-863
7.5
2020-09-24 CVE-2020-3477 Incorrect Authorization vulnerability in Cisco IOS 16.3.11
A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem.
local
low complexity
cisco CWE-863
5.5
2020-09-24 CVE-2020-3474 Incorrect Authorization vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-863
8.1
2020-09-24 CVE-2020-3404 Incorrect Authorization vulnerability in Cisco IOS XE 16.11.1
A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS) with root privileges.
local
low complexity
cisco CWE-863
7.8
2020-09-22 CVE-2020-4621 Incorrect Authorization vulnerability in IBM Data Risk Manager
IBM Data Risk Manager (iDNA) 2.0.6 could allow an authenticated user to escalate their privileges to administrator due to insufficient authorization checks.
network
low complexity
ibm CWE-863
8.8
2020-09-16 CVE-2020-2258 Incorrect Authorization vulnerability in Jenkins Health Advisor BY Cloudbees
Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint.
network
low complexity
jenkins CWE-863
4.3
2020-09-14 CVE-2020-15590 Incorrect Authorization vulnerability in Privateinternetaccess Private Internet Access VPN Client 1.5.0
A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic.
network
low complexity
privateinternetaccess CWE-863
7.5
2020-09-14 CVE-2020-13313 Incorrect Authorization vulnerability in Gitlab
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4.
network
low complexity
gitlab CWE-863
4.3