Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2022-03-07 CVE-2021-25087 Missing Authorization vulnerability in Wpdownloadmanager Wordpress Download Manager
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
network
low complexity
wpdownloadmanager CWE-862
5.0
2022-03-07 CVE-2022-0163 Missing Authorization vulnerability in Rednao Smart Forms
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on the form.
network
low complexity
rednao CWE-862
4.0
2022-03-04 CVE-2021-3656 Missing Authorization vulnerability in multiple products
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization.
local
low complexity
linux fedoraproject redhat CWE-862
8.8
2022-03-03 CVE-2022-23709 Missing Authorization vulnerability in Elastic Kibana
A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules.
network
low complexity
elastic CWE-862
4.0
2022-03-03 CVE-2022-0492 Missing Authorization vulnerability in multiple products
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function.
7.8
2022-02-28 CVE-2021-41112 Missing Authorization vulnerability in Pagerduty Rundeck
Rundeck is an open source automation service with a web console, command line tools and a WebAPI.
network
low complexity
pagerduty CWE-862
5.5
2022-02-28 CVE-2021-24730 Missing Authorization vulnerability in Infornweb Logo Showcase With Slick Slider
The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lswss_save_attachment_data AJAX action, allowing any authenticated users, such as Subscriber, to change title, description, alt text, and URL of arbitrary uploaded media.
network
low complexity
infornweb CWE-862
4.3
2022-02-28 CVE-2021-24977 Missing Authorization vulnerability in USE ANY Font Project USE ANY Font
The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to sent arbitrary CSS which will then be processed by the frontend for all users.
network
low complexity
use-any-font-project CWE-862
6.1
2022-02-28 CVE-2021-25042 Missing Authorization vulnerability in Plugins-Market WP Visitor Statistics (Real Time Traffic)
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude.
3.5
2022-02-28 CVE-2022-0345 Missing Authorization vulnerability in Madewithfuel Customize Wordpress Emails and Alerts
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.).
network
low complexity
madewithfuel CWE-862
4.3