Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-09-08 CVE-2021-1835 Missing Authorization vulnerability in Apple Iphone OS
This issue was addressed with improved checks.
low complexity
apple CWE-862
4.6
2021-09-07 CVE-2021-38698 Missing Authorization vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic.
network
low complexity
hashicorp CWE-862
6.5
2021-09-01 CVE-2021-40378 Missing Authorization vulnerability in Comprotech products
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices.
network
low complexity
comprotech CWE-862
8.1
2021-09-01 CVE-2021-40379 Missing Authorization vulnerability in Comprotech products
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices.
network
low complexity
comprotech CWE-862
7.5
2021-08-31 CVE-2021-36232 Missing Authorization vulnerability in Unit4 Mik.Starlight 7.9.5.24363
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
network
low complexity
unit4 CWE-862
8.8
2021-08-25 CVE-2021-40088 Missing Authorization vulnerability in Primekey Ejbca
An issue was discovered in PrimeKey EJBCA before 7.6.0.
network
low complexity
primekey CWE-862
5.4
2021-08-24 CVE-2021-30874 Missing Authorization vulnerability in Apple Ipados and Iphone OS
An authorization issue was addressed with improved state management.
network
low complexity
apple CWE-862
7.5
2021-08-20 CVE-2020-25359 Missing Authorization vulnerability in Rconfig 3.9.5
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6.
network
low complexity
rconfig CWE-862
critical
9.1
2021-08-20 CVE-2020-27464 Missing Authorization vulnerability in Rconfig
An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via a crafted ZIP file.
local
low complexity
rconfig CWE-862
7.8
2021-08-20 CVE-2020-27466 Missing Authorization vulnerability in Rconfig 3.9.6
An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a crafted file.
local
low complexity
rconfig CWE-862
7.8