The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,104 vulnerabilities with CWE-863
CVE-2020-24264
CRITICAL
Portainer < 1.24.1 - Incorrect Authorization Leading to Remote Code Execution via Bind Mount Bypass
CVSS 9.8
CVE-2020-25240
HIGH
SINEMA Remote Connect Server < 3.0 - Unauthenticated Incorrect Authorization via URL Guessing
CVSS 8.8
CVE-2020-25239
HIGH
SINEMA Remote Connect Server < 3.0 - Unauthorized UMC Authorization Server Modification via Special URLs
CVSS 8.8
CVE-2020-35682
HIGH
ManageEngine ServiceDesk Plus < 11134 - Authentication Bypass via SAML Login
CVSS 8.8
CVE-2020-29020
CRITICAL
Secomea SiteManager < 9.4.620527004 - Improper Access Control in Web Service
CVSS 9.1
CVE-2020-12668
MEDIUM
Jinjava < 2.5.4 - Arbitrary Class Access and Arbitrary File Disclosure via Java Method Calls
CVSS 6.5
CVE-2020-8806
HIGH
Electric Coin Company Zcashd <2.1.1-1 - DoS
CVSS 7.5
CVE-2020-27873
MEDIUM
NETGEAR AC2100 R7450 < 1.2.0.76 - Unauthenticated Sensitive Information Disclosure via SOAP API
CVSS 6.5
CVE-2020-29605
MEDIUM
MantisBT < 2.24.4 - Authenticated Private Issue Summary Exposure via bug_actiongroup_page.php
CVSS 4.3
CVE-2020-1725
MEDIUM
Keycloak < 13.0.0 - Incorrect Authorization
CVSS 5.4
CVE-2020-9492
HIGH
Apache Hadoop 2.0.0-2.10.0 and 3.0.0-alpha1-3.2.1 - Incorrect Authorization via WebHDFS SPNEGO Header
CVSS 8.8
CVE-2020-4873
MEDIUM
IBM Planning Analytics 2.0 - Sensitive Information Exposure via Overly Permissive CORS Policy
CVSS 5.3
CVE-2020-35948
CRITICAL
XCloner Backup and Restore 4.2.1-4.2.12 - Arbitrary File Write & RCE via xcloner_restore.php
CVSS 9.9
CVE-2020-26029
MEDIUM
Zammad < 3.4.1 - Incorrect Authorization via X-On-Behalf-Of Header
CVSS 6.5
CVE-2020-26028
MEDIUM
Zammad < 3.4.1 - Incorrect Authorization for Admin Users
CVSS 4.9
CVE-2020-24674
HIGH
S+ Operations/S+ Historian - DoS/Code Injection
CVSS 8.8
CVE-2020-4794
MEDIUM
IBM Automation Workstream Services 19.0.3, 20.0.1-20.0.2 - Authenticated Information Disclosure and Denial of Service
CVSS 5.4
CVE-2020-0481
LOW
Android 11 - Unauthenticated Permissions Bypass via Broadcast Intent
CVSS 3.3
CVE-2020-0479
HIGH
Android 11 - Unauthenticated Permissions Bypass in DocumentsProvider
CVSS 7.8
CVE-2020-0473
MEDIUM
Android - Local Privilege Escalation via Bluetooth File Transfer
CVSS 4.6
CVE-2020-8919
LOW
Gerrit 2.15.0-2.15.20 - Unauthenticated Information Disclosure via Branch REST API
CVSS 3.5
CVE-2020-29454
MEDIUM
Umbraco CMS < 8.9.1 - Incorrect Authorization in LogViewer Endpoint
CVSS 4.3
CVE-2020-26250
MEDIUM
OAuthenticator <0.12.2 - Info Disclosure
CVSS 6.3
CVE-2020-29374
LOW
Linux kernel <5.7.3 - Memory Corruption
CVSS 3.6
CVE-2020-15248
MEDIUM
October CMS <1.0.470 - Privilege Escalation
CVSS 4.0
Details
Vulnerabilities
3,104
Exploit Likelihood
High