Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-03-15 CVE-2021-28375 Missing Authorization vulnerability in multiple products
An issue was discovered in the Linux kernel through 5.11.6.
local
low complexity
linux fedoraproject netapp CWE-862
7.8
2021-03-11 CVE-2021-28154 Missing Authorization vulnerability in Camunda Modeler
Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access.
network
low complexity
camunda CWE-862
critical
9.1
2021-03-11 CVE-2021-28141 Missing Authorization vulnerability in Telerik UI for Asp.Net Ajax 2021.1.224
An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224.
network
low complexity
telerik CWE-862
critical
9.8
2021-03-10 CVE-2021-0389 Missing Authorization vulnerability in Google Android 11.0
In setNightModeActivated of UiModeManagerService.java, there is a missing permission check.
local
low complexity
google CWE-862
4.6
2021-03-10 CVE-2021-0388 Missing Authorization vulnerability in Google Android 11.0
In onReceive of ImsPhoneCallTracker.java, there is a possible misattribution of data usage due to an incorrect broadcast handler.
local
low complexity
google CWE-862
4.6
2021-03-10 CVE-2021-0385 Missing Authorization vulnerability in Google Android 11.0
In createConnectToAvailableNetworkNotification of ConnectToNetworkNotificationBuilder.java, there is a possible connection to untrusted WiFi networks due to notification interaction above the lockscreen.
local
low complexity
google CWE-862
4.6
2021-03-10 CVE-2021-0380 Missing Authorization vulnerability in Google Android 11.0
In onReceive of DcTracker.java, there is a possible way to trigger a provisioning URL and modify other telephony settings due to a missing permission check.
local
low complexity
google CWE-862
4.6
2021-03-10 CVE-2021-0390 Missing Authorization vulnerability in Google Android
In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check.
local
low complexity
google CWE-862
4.6
2021-03-09 CVE-2021-21487 Missing Authorization vulnerability in SAP Payment Engine 500
SAP Payment Engine version 500, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
6.5
2021-03-09 CVE-2021-21486 Missing Authorization vulnerability in SAP Enterprise Financial Services
SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
6.5