Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2019-11-06 CVE-2019-6121 Missing Authorization vulnerability in Nicehash Miner
An issue was discovered in NiceHash Miner before 2.0.3.0.
network
high complexity
nicehash CWE-862
3.7
2019-11-06 CVE-2019-18674 Missing Authorization vulnerability in Joomla Joomla!
An issue was discovered in Joomla! before 3.9.13.
network
low complexity
joomla CWE-862
5.3
2019-11-01 CVE-2019-16909 Missing Authorization vulnerability in Infosysta In-App & Desktop Notifications 1.6.13J8
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app before 1.6.14_J8 for Jira.
network
low complexity
infosysta CWE-862
4.3
2019-10-31 CVE-2019-16907 Missing Authorization vulnerability in Infosysta In-App & Desktop Notifications 1.6.13J8
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira.
network
low complexity
infosysta CWE-862
5.3
2019-10-31 CVE-2019-16906 Missing Authorization vulnerability in Infosysta In-App & Desktop Notifications 1.6.13J8
An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira.
network
low complexity
infosysta CWE-862
7.5
2019-10-31 CVE-2019-5095 Missing Authorization vulnerability in Tempo 4.10.0
An issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin, version 4.10.0.
network
low complexity
tempo CWE-862
4.3
2019-10-23 CVE-2019-18383 Missing Authorization vulnerability in Terra-Master Fs-210 Firmware 4.0.19
An issue was discovered on TerraMaster FS-210 4.0.19 devices.
network
low complexity
terra-master CWE-862
7.5
2019-10-17 CVE-2019-15850 Missing Authorization vulnerability in Eq-3 Homematic Ccu3 Firmware 3.41.11
eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method.
network
low complexity
eq-3 CWE-862
8.8
2019-10-16 CVE-2019-16698 Missing Authorization vulnerability in DKD Direct Mail
The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and export data of frontend users who are subscribed to a newsletter.
network
low complexity
dkd CWE-862
4.3
2019-10-16 CVE-2019-10457 Missing Authorization vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic 1.0.0
A missing permission check in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
network
low complexity
jenkins CWE-862
4.3