Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-04-15 CVE-2019-20676 Missing Authorization vulnerability in Netgear products
Certain NETGEAR devices are affected by lack of access control at the function level.
local
low complexity
netgear CWE-862
6.0
2020-04-15 CVE-2020-7278 Missing Authorization vulnerability in Mcafee Endpoint Security
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled correctly when updating to the February 2020 updates.
network
low complexity
mcafee CWE-862
6.5
2020-04-14 CVE-2020-6233 Missing Authorization vulnerability in SAP products
SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization Check, resulting in slowing the system.
network
low complexity
sap CWE-862
4.3
2020-04-14 CVE-2020-6232 Missing Authorization vulnerability in SAP Commerce Cloud 1811/1905
SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check.
network
low complexity
sap CWE-862
5.3
2020-04-08 CVE-2018-21047 Missing Authorization vulnerability in Google Android 8.0/8.1
An issue was discovered on Samsung mobile devices with O(8.x) software.
network
low complexity
google CWE-862
7.5
2020-04-08 CVE-2018-21046 Missing Authorization vulnerability in Google Android 8.0/8.1
An issue was discovered on Samsung mobile devices with O(8.x) software.
low complexity
google CWE-862
2.4
2020-04-08 CVE-2018-21042 Missing Authorization vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software.
network
low complexity
google CWE-862
critical
9.8
2020-04-07 CVE-2020-9514 Missing Authorization vulnerability in Idxbroker Impress for IDX Broker
An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress.
network
low complexity
idxbroker CWE-862
6.5
2020-04-07 CVE-2020-11514 Missing Authorization vulnerability in Rankmath SEO
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
network
low complexity
rankmath CWE-862
critical
9.8
2020-04-07 CVE-2017-18677 Missing Authorization vulnerability in Google Android
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software.
network
low complexity
google CWE-862
7.5