The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,104 vulnerabilities with CWE-863
CVE-2020-3522
MEDIUM
Cisco Data Center Network Manager < 11.4(1) - Authenticated Authorization Bypass via Crafted URL
CVSS 6.3
CVE-2020-19005
MEDIUM
zrlog 2.1.0 - Incorrect Authorization for Database Backup Download
CVSS 5.7
CVE-2020-16241
MEDIUM
Philips SureSigns VS4 Firmware < a.07.107 - Improper Access Control
CVSS 6.3
CVE-2020-9712
MEDIUM
Adobe Acrobat and Reader DC - Security Feature Bypass via Incorrect Authorization
CVSS 5.5
CVE-2020-3472
MEDIUM
Cisco Webex Meetings - Info Disclosure
CVSS 5.0
CVE-2020-3413
MEDIUM
Cisco Webex Meetings - Privilege Escalation
CVSS 4.3
CVE-2020-3412
MEDIUM
Cisco Webex Meetings - Privilege Escalation
CVSS 4.3
CVE-2020-8212
CRITICAL
Citrix XenMobile <10.12 - Privilege Escalation
CVSS 9.8
CVE-2020-7583
HIGH
Siemens Automation License Manager 5.x and 6.x < 6.0.8 - Improper Authorization
CVSS 7.8
CVE-2020-7300
MEDIUM
McAfee Data Loss Prevention < 11.3.28 - Authenticated Configuration Change via HTTP Post Messages
CVSS 4.6
CVE-2020-2233
MEDIUM
Jenkins Pipeline Maven Integration Plugin <3.8.2 - Info Disclosure
CVSS 6.5
CVE-2020-17448
HIGH
Telegram Desktop <2.1.13 - Info Disclosure
CVSS 7.8
CVE-2020-12780
HIGH
Combodo iTop < 2.7.1 - Sensitive Information Exposure via Security Misconfiguration
CVSS 7.5
CVE-2020-3386
HIGH
Cisco Data Center Network Manager < 11.4(1) - Authenticated Improper Authorization via REST API
CVSS 8.8
CVE-2020-3374
CRITICAL
Cisco SD-WAN vManage Software - Auth Bypass
CVSS 9.9
CVE-2020-14486
MEDIUM
OpenClinic GA 5.09.02 and 5.89.05b - Improper Authorization via Redirect Bypass
CVSS 6.3
CVE-2020-15120
MEDIUM
I hate money <4.1.5 - Privilege Escalation
CVSS 4.9
CVE-2020-15126
MEDIUM
Parser-Server <4.3.0 - Privilege Escalation
CVSS 6.5
CVE-2020-15110
MEDIUM
jupyterhub-kubespawner <0.12 - Privilege Escalation
CVSS 6.8
CVE-2020-3150
MEDIUM
Cisco Small Business RV110W/RV215W - Info Disclosure
CVSS 5.9
CVE-2020-3140
CRITICAL
Cisco Prime License Manager - Privilege Escalation
CVSS 9.8
CVE-2020-2228
HIGH
Jenkins Gitlab Auth Plugin <1.5 - Privilege Escalation
CVSS 8.8
CVE-2020-7692
HIGH
Google OAuth Client Library for Java < 1.31.0 - Incorrect Authorization via Missing PKCE Implementation
CVSS 7.4
CVE-2020-15513
MEDIUM
mittwald/typo3_forum < 1.2.1 - Incorrect Access Control
CVSS 5.3
CVE-2020-5372
HIGH
Dell EMC PowerStore < 1.0.1.0.5.002 - Unauthenticated Denial of Service via Exposed Test Interface Ports
CVSS 8.6
Details
Vulnerabilities
3,104
Exploit Likelihood
High