Vulnerabilities > Missing Authorization
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-14 | CVE-2021-24352 | Missing Authorization vulnerability in Wpdeveloper Simple 301 Redirects The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to export a site's redirects. | 8.8 |
2021-06-14 | CVE-2021-24353 | Missing Authorization vulnerability in Wpdeveloper Simple 301 Redirects The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or nonce checks making it possible for unauthenticated users to import a set of site redirects. | 8.8 |
2021-06-14 | CVE-2021-24354 | Missing Authorization vulnerability in Wpdeveloper Simple 301 Redirects A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, made it possible for authenticated users to install arbitrary plugins on vulnerable sites. | 6.5 |
2021-06-14 | CVE-2021-24355 | Missing Authorization vulnerability in Wpdeveloper Simple 301 Redirects In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient nonce check on the AJAX actions, simple301redirects/admin/get_wildcard and simple301redirects/admin/wildcard, made it possible for authenticated users to retrieve and update the wildcard value for redirects. | 4.3 |
2021-06-14 | CVE-2021-24356 | Missing Authorization vulnerability in Wpdeveloper Simple 301 Redirects In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient nonce check on the AJAX action, simple301redirects/admin/activate_plugin, made it possible for authenticated users to activate arbitrary plugins installed on vulnerable sites. | 8.8 |
2021-06-11 | CVE-2021-21382 | Missing Authorization vulnerability in Wire Restund 0.4.12/0.4.13/0.4.14 Restund is an open source NAT traversal server. | 9.6 |
2021-06-11 | CVE-2021-0491 | Missing Authorization vulnerability in Google Android In memory management driver, there is a possible escalation of privilege due to a missing permission check. | 7.2 |
2021-06-11 | CVE-2021-22896 | Missing Authorization vulnerability in Nextcloud Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authenticated users to create mail aliases for other users. | 4.0 |
2021-06-11 | CVE-2021-23204 | Missing Authorization vulnerability in Gallagher Command Centre 8.30/8.30.1236/8.30.1299 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gallagher Command Centre Server allows OSDP key material to be exposed to Command Centre Operators. | 4.0 |
2021-06-11 | CVE-2021-25409 | Missing Authorization vulnerability in Google Android 10.0 Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device. | 2.1 |