The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,104 vulnerabilities with CWE-863
CVE-2020-5240
HIGH
wagtail-2fa < 1.4.1 - Improper Authorization via 2FA Device Management Path
CVSS 7.6
CVE-2020-10534
CRITICAL
MediaWiki <1.34.0 - Privilege Escalation
CVSS 9.8
CVE-2020-0087
MEDIUM
Android 10 - Unauthenticated Side Channel Information Disclosure in ActivityManagerService
CVSS 5.5
CVE-2020-0036
HIGH
Android 8.0-10 - Incorrect Authorization in PermissionMonitor
CVSS 7.8
CVE-2020-2148
MEDIUM
Jenkins Mac Plugin < 1.1.0 - Missing Permission Check for SSH Connection
CVSS 4.3
CVE-2020-2135
HIGH
Jenkins Script Security Plugin < 1.70 - Sandbox Bypass via GroovyInterceptable Method Calls
CVSS 8.8
CVE-2020-2134
HIGH
Jenkins Script Security Plugin < 1.70 - Sandbox Bypass via Crafted Constructor Calls
CVSS 8.8
CVE-2020-5251
HIGH
parse-server < 4.1.0 - Improper Authorization via NoSQL Query Regex
CVSS 7.7
CVE-2020-9381
HIGH
Total.js CMS 13 - Unauthenticated Remote Code Execution via Admin Widgets API
CVSS 7.5
CVE-2020-5242
HIGH
openHAB < 2.5.2 - Unauthenticated Remote Code Execution via REST API Binding Installation
CVSS 7.7
CVE-2020-7251
MEDIUM
McAfee ENS <10.6.1 - Info Disclosure
CVSS 5.0
CVE-2020-5239
HIGH
Mailu < 1.7 - Authenticated Privilege Escalation via Fetchmail Script
CVSS 8.7
CVE-2020-6380
HIGH
Google Chrome <79.0.3945.130 - Privilege Escalation
CVSS 8.8
CVE-2020-5318
HIGH
Dell EMC Isilon OneFS 8.0.0.7, 8.1.0.3, 8.1.0.4, 8.1.2 - Unauthenticated File Access via HTTP and WebDAV
CVSS 7.5
CVE-2020-8119
MEDIUM
Nextcloud server <17.0.0 - Info Disclosure
CVSS 4.3
CVE-2020-7955
MEDIUM
HashiCorp Consul <1.6.2 - Info Disclosure
CVSS 5.3
CVE-2020-2104
MEDIUM
Jenkins < 2.204.1 and < 2.218 - Incorrect Authorization for JVM Memory Usage Chart
CVSS 4.3
CVE-2020-8086
CRITICAL
Prosody mod_auth_ldap/mod_auth_ldap2 - Privilege Escalation
CVSS 9.8
CVE-2020-2097
HIGH
Jenkins Sounds Plugin < 0.5 - OS Command Execution via Form Validation URL
CVSS 8.8
CVE-2020-6307
MEDIUM
SAP Basis - Incorrect Authorization in Automated Note Search Tool
CVSS 4.3
CVE-2019-25237
CRITICAL
V-SOL GPON/EPON OLT Platform v2.03 - Privilege Escalation
CVSS 9.8
CVE-2019-25058
HIGH
USBGuard <1.1.0 - Privilege Escalation
CVSS 7.8
CVE-2019-16651
MEDIUM
Virgin Media Super Hub 3 - Info Disclosure
CVSS 5.3
CVE-2019-15059
HIGH
Liberty lisPBX 2.0-4 - Unauthenticated Sensitive Information Exposure via Backup File Retrieval
CVSS 7.5
CVE-2019-25017
MEDIUM
MIT krb5-appl <1.0.3 - Code Injection
CVSS 5.9
Details
Vulnerabilities
3,104
Exploit Likelihood
High