Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2019-07-31 CVE-2019-10187 Missing Authorization vulnerability in Moodle
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7.
network
low complexity
moodle CWE-862
4.3
2019-07-31 CVE-2019-10357 Missing Authorization vulnerability in multiple products
A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.
network
low complexity
jenkins redhat CWE-862
4.3
2019-07-31 CVE-2019-10344 Missing Authorization vulnerability in Jenkins Configuration AS Code
Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about installed plugins.
network
low complexity
jenkins CWE-862
4.3
2019-07-30 CVE-2019-10161 Missing Authorization vulnerability in multiple products
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process.
local
low complexity
redhat canonical CWE-862
7.8
2019-07-30 CVE-2019-5449 Missing Authorization vulnerability in Nextcloud Server
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
network
low complexity
nextcloud CWE-862
4.3
2019-07-25 CVE-2019-10184 Missing Authorization vulnerability in multiple products
undertow before version 2.0.23.Final is vulnerable to an information leak issue.
network
low complexity
redhat netapp CWE-862
7.5
2019-07-23 CVE-2019-11702 Missing Authorization vulnerability in Mozilla Firefox
A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted.
network
low complexity
mozilla CWE-862
6.5
2019-07-23 CVE-2019-11700 Missing Authorization vulnerability in Mozilla Firefox
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted.
network
low complexity
mozilla CWE-862
6.5
2019-07-23 CVE-2019-1010152 Missing Authorization vulnerability in Zzcms
zzcms 8.3 and earlier is affected by: File Delete to Code Execution.
network
low complexity
zzcms CWE-862
critical
9.8
2019-07-23 CVE-2019-1010150 Missing Authorization vulnerability in Zzcms
zzcms 8.3 and earlier is affected by: File Delete to Code Execution.
network
low complexity
zzcms CWE-862
critical
9.8