The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,104 vulnerabilities with CWE-863
CVE-2020-14196
MEDIUM
PowerDNS Recursor <= 4.1.16 - Incorrect Authorization
CVSS 5.3
CVE-2020-15084
HIGH
express-jwt < 5.3.3 - Authorization Bypass via Unenforced Algorithms Configuration
CVSS 7.7
CVE-2020-12053
CRITICAL
Unisys Stealth 3.4.x-5.x < 5.0.026 - Incorrect Authorization via Certificate-Based Endpoint
CVSS 9.8
CVE-2020-13263
HIGH
GitLab EE 9.5-13.0.1 - Incorrect Authorization via Project Maintainer Impersonation
CVSS 7.5
CVE-2020-13277
MEDIUM
GitLab CE/EE <13.0.5 - Info Disclosure
CVSS 6.3
CVE-2020-3364
MEDIUM
Cisco IOS XR - Unauthenticated Access Control Bypass via Standby Route Processor Management Interface
CVSS 5.3
CVE-2020-3360
MEDIUM
Cisco IP Phones Series 7800-8800 - Info Disclosure
CVSS 5.3
CVE-2020-6752
LOW
OMERO < 5.6.1 - Incorrect Authorization
CVSS 3.8
CVE-2020-14214
MEDIUM
Zammad < 3.3.1 - Unauthenticated Incorrect Authorization via Domain Based Assignment
CVSS 6.5
CVE-2020-7499
MEDIUM
Schneider Electric U.motion Servers and Touch Panels < 1.4.2 - Incorrect Authorization
CVSS 6.5
CVE-2020-0115
HIGH
Android 8.0-10 - Incorrect Authorization in PackageManagerService
CVSS 7.8
CVE-2020-13696
MEDIUM
xawtv < 3.107 - Unauthenticated Arbitrary File Access via v4l-conf Device Path Manipulation
CVSS 4.4
CVE-2020-13834
HIGH
Android O(8.x), P(9.0), Q(10.0) - Incorrect Authorization in Secure Folder
CVSS 7.5
CVE-2020-3335
MEDIUM
Cisco Application Services Engine Software - Info Disclosure
CVSS 5.5
CVE-2020-3231
MEDIUM
Cisco IOS - Unauthenticated Broadcast Traffic Forwarding via 802.1X Port Mishandling
CVSS 4.7
CVE-2020-3229
HIGH
Cisco IOS XE Web Management Software - Privilege Escalation
CVSS 8.8
CVE-2020-3227
CRITICAL
Cisco IOS XE - Unauthenticated API Command Execution via Crafted Token Request
CVSS 9.8
CVE-2020-4026
MEDIUM
Atlassian Navigator Links < 3.3.23, 4.0.0-4.3.6, 5.0.0, 5.1.0 - Incorrect Authorization in CustomAppsRestResource
CVSS 4.3
CVE-2020-11844
CRITICAL
Micro Focus Service Management Automation 2018.05-2020.02 - Incorrect Authorization
CVSS 10.0
CVE-2020-1831
LOW
HUAWEI Mate 20 <10.0.0.195 - Privilege Escalation
CVSS 2.4
CVE-2020-4249
MEDIUM
IBM Security Identity Governance and Intelligence 5.2.6 - Sensitive Information Disclosure via Incorrect Authorization
CVSS 6.5
CVE-2020-12391
HIGH
Firefox < 76.0 - Cross-Origin Script Execution via data: URL in OBJECT Element
CVSS 7.5
CVE-2020-3811
HIGH
netqmail - Mail-Address Verification Bypass via qmail-verify
CVSS 7.5
CVE-2020-0097
HIGH
Android 9-10 - Incorrect Authorization in PackageManagerService
CVSS 7.8
CVE-2020-12876
HIGH
Veritas APTARE <10.4 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
3,104
Exploit Likelihood
High