CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,104 vulnerabilities with CWE-863
CVE-2020-5240 HIGH
wagtail-2fa < 1.4.1 - Improper Authorization via 2FA Device Management Path
CVSS 7.6
CVE-2020-10534 CRITICAL
MediaWiki <1.34.0 - Privilege Escalation
CVSS 9.8
CVE-2020-0087 MEDIUM
Android 10 - Unauthenticated Side Channel Information Disclosure in ActivityManagerService
CVSS 5.5
CVE-2020-0036 HIGH
Android 8.0-10 - Incorrect Authorization in PermissionMonitor
CVSS 7.8
CVE-2020-2148 MEDIUM
Jenkins Mac Plugin < 1.1.0 - Missing Permission Check for SSH Connection
CVSS 4.3
CVE-2020-2135 HIGH
Jenkins Script Security Plugin < 1.70 - Sandbox Bypass via GroovyInterceptable Method Calls
CVSS 8.8
CVE-2020-2134 HIGH
Jenkins Script Security Plugin < 1.70 - Sandbox Bypass via Crafted Constructor Calls
CVSS 8.8
CVE-2020-5251 HIGH
parse-server < 4.1.0 - Improper Authorization via NoSQL Query Regex
CVSS 7.7
CVE-2020-9381 HIGH
Total.js CMS 13 - Unauthenticated Remote Code Execution via Admin Widgets API
CVSS 7.5
CVE-2020-5242 HIGH
openHAB < 2.5.2 - Unauthenticated Remote Code Execution via REST API Binding Installation
CVSS 7.7
CVE-2020-7251 MEDIUM
McAfee ENS <10.6.1 - Info Disclosure
CVSS 5.0
CVE-2020-5239 HIGH
Mailu < 1.7 - Authenticated Privilege Escalation via Fetchmail Script
CVSS 8.7
CVE-2020-6380 HIGH
Google Chrome <79.0.3945.130 - Privilege Escalation
CVSS 8.8
CVE-2020-5318 HIGH
Dell EMC Isilon OneFS 8.0.0.7, 8.1.0.3, 8.1.0.4, 8.1.2 - Unauthenticated File Access via HTTP and WebDAV
CVSS 7.5
CVE-2020-8119 MEDIUM
Nextcloud server <17.0.0 - Info Disclosure
CVSS 4.3
CVE-2020-7955 MEDIUM
HashiCorp Consul <1.6.2 - Info Disclosure
CVSS 5.3
CVE-2020-2104 MEDIUM
Jenkins < 2.204.1 and < 2.218 - Incorrect Authorization for JVM Memory Usage Chart
CVSS 4.3
CVE-2020-8086 CRITICAL
Prosody mod_auth_ldap/mod_auth_ldap2 - Privilege Escalation
CVSS 9.8
CVE-2020-2097 HIGH
Jenkins Sounds Plugin < 0.5 - OS Command Execution via Form Validation URL
CVSS 8.8
CVE-2020-6307 MEDIUM
SAP Basis - Incorrect Authorization in Automated Note Search Tool
CVSS 4.3
CVE-2019-25237 CRITICAL
V-SOL GPON/EPON OLT Platform v2.03 - Privilege Escalation
CVSS 9.8
CVE-2019-25058 HIGH
USBGuard <1.1.0 - Privilege Escalation
CVSS 7.8
CVE-2019-16651 MEDIUM
Virgin Media Super Hub 3 - Info Disclosure
CVSS 5.3
CVE-2019-15059 HIGH
Liberty lisPBX 2.0-4 - Unauthenticated Sensitive Information Exposure via Backup File Retrieval
CVSS 7.5
CVE-2019-25017 MEDIUM
MIT krb5-appl <1.0.3 - Code Injection
CVSS 5.9
Details
Vulnerabilities 3,104
Exploit Likelihood High