Vulnerabilities > Missing Authorization
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-05-30 | CVE-2022-1203 | Missing Authorization vulnerability in Content Mask Project Content Mask The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin. | 4.3 |
2022-05-24 | CVE-2020-4926 | Missing Authorization vulnerability in IBM Elastic Storage System and Spectrum Scale A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. | 9.1 |
2022-05-20 | CVE-2022-28993 | Missing Authorization vulnerability in Bdtask Multi Store Inventory Management System 1.0 Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request. | 9.8 |
2022-05-19 | CVE-2022-1423 | Missing Authorization vulnerability in Gitlab Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches | 8.8 |
2022-05-18 | CVE-2021-42848 | Missing Authorization vulnerability in Lenovo products An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details. | 5.3 |
2022-05-17 | CVE-2022-30951 | Missing Authorization vulnerability in Jenkins WMI Windows Agents Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in. | 8.8 |
2022-05-17 | CVE-2022-30954 | Missing Authorization vulnerability in Jenkins Blue Ocean Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server. | 6.5 |
2022-05-17 | CVE-2022-30955 | Missing Authorization vulnerability in Jenkins Gitlab Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | 6.5 |
2022-05-17 | CVE-2022-30957 | Missing Authorization vulnerability in Jenkins SSH A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | 4.3 |
2022-05-17 | CVE-2022-30959 | Missing Authorization vulnerability in Jenkins SSH A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | 6.5 |