Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-07-27 CVE-2021-32748 Missing Authorization vulnerability in Nextcloud Richdocuments
Nextcloud Richdocuments in an open source self hosted online office.
network
low complexity
nextcloud CWE-862
4.3
2021-07-15 CVE-2020-12734 Missing Authorization vulnerability in Depstech Wifi Digital Microscope 3 Firmware
DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment from the rightful device owner, because there is no way to reset to Factory Default settings.
low complexity
depstech CWE-862
8.1
2021-07-14 CVE-2021-0518 Missing Authorization vulnerability in Google Android 13.0
In Wi-Fi, there is a possible leak of location-sensitive data due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-07-14 CVE-2021-0597 Missing Authorization vulnerability in Google Android
In notifyProfileAdded and notifyProfileRemoved of SipService.java, there is a possible way to retrieve SIP account names due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-07-14 CVE-2021-0654 Missing Authorization vulnerability in Google Android
In isRealSnapshot of TaskThumbnailView.java, there is possible data exposure due to a missing permission check.
local
low complexity
google CWE-862
5.5
2021-07-14 CVE-2021-33671 Missing Authorization vulnerability in SAP Netweaver Guided Procedures
SAP NetWeaver Guided Procedures (Administration Workset), versions - 7.10, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
8.8
2021-07-14 CVE-2021-33676 Missing Authorization vulnerability in SAP Customer Relationship Management
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
network
low complexity
sap CWE-862
7.2
2021-07-14 CVE-2021-20747 Missing Authorization vulnerability in Retty
Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
network
low complexity
retty CWE-862
4.3
2021-07-13 CVE-2021-36124 Missing Authorization vulnerability in Echobh Sharecare 8.15.5
An issue was discovered in Echo ShareCare 8.15.5.
network
low complexity
echobh CWE-862
critical
9.8
2021-07-12 CVE-2020-19038 Missing Authorization vulnerability in Halo 0.4.3
File Deletion vulnerability in Halo 0.4.3 via delBackup.
network
low complexity
halo CWE-862
critical
9.1