Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-04-08 CVE-2018-21046 Missing Authorization vulnerability in Google Android 8.0/8.1
An issue was discovered on Samsung mobile devices with O(8.x) software.
local
low complexity
google CWE-862
2.1
2020-04-08 CVE-2018-21042 Missing Authorization vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software.
network
low complexity
google CWE-862
7.5
2020-04-08 CVE-2020-11601 Missing Authorization vulnerability in Google Android 10.0/9.0
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software.
local
low complexity
google CWE-862
2.1
2020-04-07 CVE-2020-11514 Missing Authorization vulnerability in Rankmath SEO
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
network
low complexity
rankmath CWE-862
critical
9.8
2020-04-07 CVE-2017-18677 Missing Authorization vulnerability in Google Android
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software.
network
low complexity
google CWE-862
5.0
2020-04-07 CVE-2017-18666 Missing Authorization vulnerability in Google Android
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software.
network
low complexity
google CWE-862
5.0
2020-04-07 CVE-2016-11036 Missing Authorization vulnerability in Google Android 6.0
An issue was discovered on Samsung mobile devices with M(6.0) software.
network
low complexity
google CWE-862
7.5
2020-04-02 CVE-2020-9349 Missing Authorization vulnerability in Cacagoo Tv-288Zd-2Mp Firmware 3.4.2.0919
The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service without a password.
network
low complexity
cacagoo CWE-862
5.0
2020-04-01 CVE-2020-11470 Missing Authorization vulnerability in Zoom Meetings 4.6.8
Zoom Client for Meetings through 4.6.8 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Zoom Client's microphone and camera access.
local
low complexity
zoom CWE-862
2.1
2020-04-01 CVE-2020-3891 Missing Authorization vulnerability in Apple Ipad OS and Iphone OS
A logic issue was addressed with improved state management.
local
low complexity
apple CWE-862
2.1