Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2019-09-05 CVE-2019-15954 Missing Authorization vulnerability in Totaljs Total.Js CMS 12.0.0
An issue was discovered in Total.js CMS 12.0.0.
network
low complexity
totaljs CWE-862
critical
9.9
2019-09-05 CVE-2019-15953 Missing Authorization vulnerability in Totaljs Total.Js CMS 12.0.0
An issue was discovered in Total.js CMS 12.0.0.
network
low complexity
totaljs CWE-862
8.8
2019-09-03 CVE-2019-15871 Missing Authorization vulnerability in Wpbrigade Loginpress
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
network
low complexity
wpbrigade CWE-862
4.3
2019-08-29 CVE-2019-13408 Missing Authorization vulnerability in multiple products
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230.
network
low complexity
androvideo geovision CWE-862
7.5
2019-08-29 CVE-2019-11248 Missing Authorization vulnerability in Kubernetes
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port.
network
low complexity
kubernetes CWE-862
8.2
2019-08-27 CVE-2019-15648 Missing Authorization vulnerability in Elearningfreak Insert or Embed Articulate Content
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
network
low complexity
elearningfreak CWE-862
6.5
2019-08-23 CVE-2019-13013 Missing Authorization vulnerability in Obdev Little Snitch 4.3.0/4.3.1/4.3.2
Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool.
local
low complexity
obdev CWE-862
5.5
2019-08-23 CVE-2019-8445 Missing Authorization vulnerability in Atlassian Jira Server
Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check.
network
low complexity
atlassian CWE-862
5.3
2019-08-20 CVE-2019-2137 Missing Authorization vulnerability in Google Android 9.0
In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check.
local
low complexity
google CWE-862
5.5
2019-08-18 CVE-2019-15136 Missing Authorization vulnerability in Eprosima Fast-Rtps
The Access Control plugin in eProsima Fast RTPS through 1.9.0 does not check partition permissions from remote participant connections, which can lead to policy bypass for a secure Data Distribution Service (DDS) partition.
network
low complexity
eprosima CWE-862
7.5