CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,104 vulnerabilities with CWE-863
CVE-2020-14196 MEDIUM
PowerDNS Recursor <= 4.1.16 - Incorrect Authorization
CVSS 5.3
CVE-2020-15084 HIGH
express-jwt < 5.3.3 - Authorization Bypass via Unenforced Algorithms Configuration
CVSS 7.7
CVE-2020-12053 CRITICAL
Unisys Stealth 3.4.x-5.x < 5.0.026 - Incorrect Authorization via Certificate-Based Endpoint
CVSS 9.8
CVE-2020-13263 HIGH
GitLab EE 9.5-13.0.1 - Incorrect Authorization via Project Maintainer Impersonation
CVSS 7.5
CVE-2020-13277 MEDIUM
GitLab CE/EE <13.0.5 - Info Disclosure
CVSS 6.3
CVE-2020-3364 MEDIUM
Cisco IOS XR - Unauthenticated Access Control Bypass via Standby Route Processor Management Interface
CVSS 5.3
CVE-2020-3360 MEDIUM
Cisco IP Phones Series 7800-8800 - Info Disclosure
CVSS 5.3
CVE-2020-6752 LOW
OMERO < 5.6.1 - Incorrect Authorization
CVSS 3.8
CVE-2020-14214 MEDIUM
Zammad < 3.3.1 - Unauthenticated Incorrect Authorization via Domain Based Assignment
CVSS 6.5
CVE-2020-7499 MEDIUM
Schneider Electric U.motion Servers and Touch Panels < 1.4.2 - Incorrect Authorization
CVSS 6.5
CVE-2020-0115 HIGH
Android 8.0-10 - Incorrect Authorization in PackageManagerService
CVSS 7.8
CVE-2020-13696 MEDIUM
xawtv < 3.107 - Unauthenticated Arbitrary File Access via v4l-conf Device Path Manipulation
CVSS 4.4
CVE-2020-13834 HIGH
Android O(8.x), P(9.0), Q(10.0) - Incorrect Authorization in Secure Folder
CVSS 7.5
CVE-2020-3335 MEDIUM
Cisco Application Services Engine Software - Info Disclosure
CVSS 5.5
CVE-2020-3231 MEDIUM
Cisco IOS - Unauthenticated Broadcast Traffic Forwarding via 802.1X Port Mishandling
CVSS 4.7
CVE-2020-3229 HIGH
Cisco IOS XE Web Management Software - Privilege Escalation
CVSS 8.8
CVE-2020-3227 CRITICAL
Cisco IOS XE - Unauthenticated API Command Execution via Crafted Token Request
CVSS 9.8
CVE-2020-4026 MEDIUM
Atlassian Navigator Links < 3.3.23, 4.0.0-4.3.6, 5.0.0, 5.1.0 - Incorrect Authorization in CustomAppsRestResource
CVSS 4.3
CVE-2020-11844 CRITICAL
Micro Focus Service Management Automation 2018.05-2020.02 - Incorrect Authorization
CVSS 10.0
CVE-2020-1831 LOW
HUAWEI Mate 20 <10.0.0.195 - Privilege Escalation
CVSS 2.4
CVE-2020-4249 MEDIUM
IBM Security Identity Governance and Intelligence 5.2.6 - Sensitive Information Disclosure via Incorrect Authorization
CVSS 6.5
CVE-2020-12391 HIGH
Firefox < 76.0 - Cross-Origin Script Execution via data: URL in OBJECT Element
CVSS 7.5
CVE-2020-3811 HIGH
netqmail - Mail-Address Verification Bypass via qmail-verify
CVSS 7.5
CVE-2020-0097 HIGH
Android 9-10 - Incorrect Authorization in PackageManagerService
CVSS 7.8
CVE-2020-12876 HIGH
Veritas APTARE <10.4 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 3,104
Exploit Likelihood High