Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-08-20 CVE-2020-25359 Missing Authorization vulnerability in Rconfig 3.9.5
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6.
network
low complexity
rconfig CWE-862
critical
9.1
2021-08-20 CVE-2020-27464 Missing Authorization vulnerability in Rconfig
An insecure update feature in the /updater.php component of rConfig 3.9.6 and below allows attackers to execute arbitrary code via a crafted ZIP file.
network
rconfig CWE-862
6.8
2021-08-20 CVE-2020-27466 Missing Authorization vulnerability in Rconfig 3.9.6
An arbitrary file write vulnerability in lib/AjaxHandlers/ajaxEditTemplate.php of rConfig 3.9.6 allows attackers to execute arbitrary code via a crafted file.
network
rconfig CWE-862
6.8
2021-08-18 CVE-2021-0415 Missing Authorization vulnerability in Google Android 10.0/11.0
In memory management driver, there is a possible information disclosure due to a missing permission check.
local
low complexity
google CWE-862
2.1
2021-08-17 CVE-2021-0641 Missing Authorization vulnerability in Google Android
In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check.
local
low complexity
google CWE-862
2.1
2021-08-17 CVE-2021-0642 Missing Authorization vulnerability in Google Android
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check.
network
google CWE-862
4.3
2021-08-16 CVE-2021-38755 Missing Authorization vulnerability in Hospital Management System Project Hospital Management System
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
5.0
2021-08-13 CVE-2020-18753 Missing Authorization vulnerability in Dcce Mac1100 PLC Firmware
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted packet.
network
low complexity
dcce CWE-862
7.5
2021-08-13 CVE-2020-18757 Missing Authorization vulnerability in Dcce Mac1100 PLC Firmware
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to cause persistent denial of service (DOS) via a crafted packet.
network
low complexity
dcce CWE-862
7.8
2021-08-09 CVE-2021-24501 Missing Authorization vulnerability in Amentotech Workreap
The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifying or deleting objects.
network
low complexity
amentotech CWE-862
5.5