Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2022-06-16 CVE-2021-37764 Missing Authorization vulnerability in Xos-Shop XOS Shop System 1.0.9
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/manufacturers.php.
network
low complexity
xos-shop CWE-862
5.5
2022-06-16 CVE-2021-46820 Missing Authorization vulnerability in Xos-Shop XOS Shop System 1.0.9
Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/categories.php
network
low complexity
xos-shop CWE-862
5.5
2022-06-15 CVE-2022-20736 Missing Authorization vulnerability in Cisco Appdynamics Controller
A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to access.
network
low complexity
cisco CWE-862
5.3
2022-06-15 CVE-2022-20138 Missing Authorization vulnerability in Google Android
In ACTION_MANAGED_PROFILE_PROVISIONED of DevicePolicyManagerService.java, there is a possible way for unprivileged app to send MANAGED_PROFILE_PROVISIONED intent due to a missing permission check.
local
low complexity
google CWE-862
7.8
2022-06-15 CVE-2022-20172 Missing Authorization vulnerability in Google Android
In onbind of ShannonRcsService.java, there is a possible access to protect data due to a missing permission check.
local
low complexity
google CWE-862
5.5
2022-06-15 CVE-2022-20182 Missing Authorization vulnerability in Google Android
In handle_ramdump of pixel_loader.c, there is a possible way to create a ramdump of non-secure memory due to a missing permission check.
local
low complexity
google CWE-862
4.4
2022-06-15 CVE-2022-20200 Missing Authorization vulnerability in Google Android 12.1
In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check.
local
low complexity
google CWE-862
5.5
2022-06-15 CVE-2022-20204 Missing Authorization vulnerability in Google Android 12.1
In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check.
local
low complexity
google CWE-862
7.8
2022-06-15 CVE-2022-20206 Missing Authorization vulnerability in Google Android 12.1
In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check.
local
low complexity
google CWE-862
5.5
2022-06-15 CVE-2022-20126 Missing Authorization vulnerability in Google Android
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check.
local
low complexity
google CWE-862
7.3