The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,104 vulnerabilities with CWE-863
CVE-2019-14813
CRITICAL
Ghostscript 9.00-9.49 - Unauthenticated Privilege Escalation via setsystemparams Procedure
CVSS 9.8
CVE-2019-2175
HIGH
Android 9 - Incorrect Authorization in SliceManagerService
CVSS 7.8
CVE-2019-14817
HIGH
Ghostscript < 9.50 - Privilege Escalation via Unsecured Privileged API Calls
CVSS 7.8
CVE-2019-14811
HIGH
Ghostscript < 9.50 - Privilege Escalation via .pdf_hook_DSC_Creator Bypass
CVSS 7.8
CVE-2019-11247
HIGH
Kubernetes < 1.13.9, < 1.14.5, < 1.15.2 - Unauthorized Cluster-Scoped Custom Resource Access via Namespace Impersonation
CVSS 8.1
CVE-2019-8446
MEDIUM
Jira Server 7.6-8.3.1 - Unauthenticated Username Enumeration via Issue Navigation Endpoint
CVSS 5.3
CVE-2019-8445
MEDIUM
Jira Server 7.13.0-7.13.6 and 8.0.0-8.3.1 - Unauthenticated Worklog Information Disclosure via Missing Authorization
CVSS 5.3
CVE-2019-1192
MEDIUM
Internet Explorer - Same-Origin Policy Bypass via Improper Origin Handling
CVSS 4.3
CVE-2019-13417
MEDIUM
Search Guard < 24.0 - Unauthorized Field Name Exposure via Field Caps and Mapping API
CVSS 5.3
CVE-2019-14924
HIGH
gcdwebserver < 3.5.3 - Incorrect Authorization in GCDWebUploader moveItem
CVSS 7.5
CVE-2019-1912
CRITICAL
Cisco Small Business 220 Series Smart Switches < 1.1.4.4 - Arbitrary File Upload
CVSS 9.1
CVE-2019-13386
HIGH
CentOS Web Panel 0.9.8.846 - Remote Command Execution via filemanager2.php Hidden Action
CVSS 8.8
CVE-2019-11724
MEDIUM
Firefox < 68.0 - Incorrect Authorization via Retired Site Permission
CVSS 6.1
CVE-2019-1010084
MEDIUM
Dancer::Plugin::SimpleCRUD <1.14 - Privilege Escalation
CVSS 6.5
CVE-2019-5220
MEDIUM
Multiple Smartphones <9.0.0.200 - Privilege Escalation
CVSS 4.6
CVE-2019-9149
MEDIUM
Mailvelope < 3.3.0 - Unauthenticated Private Key Operations via Client-API URL Parameter
CVSS 6.5
CVE-2019-13337
HIGH
WESEEK GROWI < 3.5.0 - Unauthenticated Authorization Bypass via access_token URL Parameter
CVSS 7.5
CVE-2019-5602
HIGH
FreeBSD Out-of-bounds Write in cdrom Driver
CVSS 8.8
CVE-2019-7258
HIGH
Linear eMerge E3-Series - Privilege Escalation
CVSS 8.8
CVE-2019-10964
HIGH
Medtronic MiniMed 508 and Paradigm Firmware - Improper Access Control via Wireless RF Communication
CVSS 7.1
CVE-2019-5838
MEDIUM
Google Chrome < 75.0.3770.80 - Insufficient Policy Enforcement in Extensions API
CVSS 4.3
CVE-2019-1626
HIGH
Cisco SD-WAN Firmware < 18.3.6 - Authenticated Privilege Escalation via vManage Web UI
CVSS 8.8
CVE-2019-6582
HIGH
Siveillance VMS <13.1a Authenticated Improper Authorization
CVSS 7.1
CVE-2019-12492
MEDIUM
Gallagher Command Centre < 7.80.939 - Incorrect Authorization
CVSS 6.5
CVE-2019-3403
MEDIUM
Jira < 7.13.3, 8.0.0-8.0.3, 8.1.0 - Unauthenticated Username Enumeration via User Picker REST Endpoint
CVSS 5.3
Details
Vulnerabilities
3,104
Exploit Likelihood
High