The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
3,104 vulnerabilities with CWE-863
CVE-2019-3401
MEDIUM
Jira < 7.13.3 and 8.0.0-8.1.1 - Unauthenticated Username Enumeration via ManageFilters.jspa
CVSS 5.3
CVE-2019-3399
HIGH
Jira <7.13.2 and 8.0.0-8.0.2 - Unauthenticated Information Disclosure via BrowseProjects.jspa
CVSS 7.5
CVE-2019-7304
CRITICAL
Canonical snapd <2.37.1 - Command Injection
CVSS 9.8
CVE-2019-6570
HIGH
SINEMA Remote Connect Server < 2.0 - Insufficient Permission Check
CVSS 8.8
CVE-2019-3842
HIGH
systemd < 242-rc4 - Improper Authorization via XDG_SEAT Environment Variable
CVSS 7.0
CVE-2019-0732
HIGH
Windows - Device Guard Bypass via LUAFV Driver Improper Call Handling
CVSS 7.8
CVE-2019-3887
MEDIUM
Linux Kernel >= 4.16 - Denial of Service via KVM x2APIC MSR Access
CVSS 5.6
CVE-2019-0762
MEDIUM
Microsoft Internet Explorer and Edge - Security Feature Bypass via Origin Handling
CVSS 4.3
CVE-2019-0761
MEDIUM
Internet Explorer - Security Feature Bypass via URL Security Zone Validation
CVSS 6.5
CVE-2019-0678
MEDIUM
Microsoft Edge - Privilege Escalation
CVSS 6.8
CVE-2019-3848
MEDIUM
moodle < 3.4.8 - Incorrect Authorization in Calendar Event Modal
CVSS 4.3
CVE-2019-3831
MEDIUM
ovirt vdsm 4.19-4.30.3 4.30.5-4.30.8 - Authenticated Remote Code Execution via systemd_run Function
CVSS 6.7
CVE-2019-3827
HIGH
gvfs < 1.39.4 - Incorrect Authorization in Admin Backend
CVSS 7.0
CVE-2019-10014
MEDIUM
DedeCMS 5.7SP2 - Authenticated Arbitrary Password Reset via ID Parameter
CVSS 6.5
CVE-2019-0276
HIGH
Banking services from SAP 9.0 and SAP S/4HANA Financial Products Subledger 1 - Incorrect Authorization
CVSS 8.8
CVE-2019-1604
HIGH
Cisco NX-OS < 7.0(3)I7(4) - Authenticated Privilege Escalation via Incorrect Group ID Authorization
CVSS 7.8
CVE-2019-1603
HIGH
Cisco NX-OS < 7.0(3)I7(4) - Authenticated Privilege Escalation via CLI
CVSS 7.8
CVE-2019-1667
LOW
Cisco HyperFlex HX Data Platform < 3.5(2a) - Authenticated Arbitrary Data Write via Graphite Interface
CVSS 3.3
CVE-2019-0105
HIGH
Intel Data Center Manager < 5.0.2 - Authenticated Privilege Escalation via Insufficient File Permissions
CVSS 7.8
CVE-2019-7639
HIGH
gsi-openssh-server 7.9p1 - Info Disclosure
CVSS 8.1
CVE-2019-0552
HIGH
Windows COM Desktop Broker - Privilege Escalation
CVSS 8.8
CVE-2018-25353
HIGH
Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File Upload
CVSS 8.8
CVE-2018-25146
HIGH
Microhard Systems IPn4G 1.1.0 - Privilege Escalation
CVSS 8.1
CVE-2018-9374
HIGH
Android - Incorrect Authorization in PackageManagerService
CVSS 7.8
CVE-2018-8724
HIGH
K7Computing Antivirus < 16.0.0001 - Privilege Escalation via K7TSMngr.exe
CVSS 7.8
Details
Vulnerabilities
3,104
Exploit Likelihood
High