Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-01-05 CVE-2019-20484 Incorrect Authorization vulnerability in Vikisolutions Vera 4.9.1.26180
An issue was discovered in Viki Vera 4.9.1.26180.
network
low complexity
vikisolutions CWE-863
5.5
2021-01-01 CVE-2020-35951 Incorrect Authorization vulnerability in Expresstech Quiz and Survey Master
An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress.
network
low complexity
expresstech CWE-863
6.4
2021-01-01 CVE-2020-35948 Incorrect Authorization vulnerability in Xcloner
An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress.
network
low complexity
xcloner CWE-863
6.5
2021-01-01 CVE-2019-25012 Incorrect Authorization vulnerability in Webform Report Project Webform Report 7.X1.Xdev
The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml page.
network
low complexity
webform-report-project CWE-863
5.0
2021-01-01 CVE-2016-20005 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
7.5
2021-01-01 CVE-2016-20004 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
7.5
2021-01-01 CVE-2016-20002 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
7.5
2021-01-01 CVE-2016-20001 Incorrect Authorization vulnerability in Rest/Json Project Rest/Json
The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033.
network
low complexity
rest-json-project CWE-863
7.5
2020-12-30 CVE-2020-35849 Incorrect Authorization vulnerability in Mantisbt
An issue was discovered in MantisBT before 2.24.4.
network
low complexity
mantisbt CWE-863
5.0
2020-12-28 CVE-2020-29160 Incorrect Authorization vulnerability in Zammad
An issue was discovered in Zammad before 3.5.1.
network
low complexity
zammad CWE-863
5.0