Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-04-07 CVE-2016-11036 Missing Authorization vulnerability in Google Android 6.0
An issue was discovered on Samsung mobile devices with M(6.0) software.
network
low complexity
google CWE-862
critical
9.8
2020-04-01 CVE-2020-11465 Missing Authorization vulnerability in Deskpro
An issue was discovered in Deskpro before 2019.8.0.
network
low complexity
deskpro CWE-862
8.8
2020-04-01 CVE-2020-11463 Missing Authorization vulnerability in Deskpro
An issue was discovered in Deskpro before 2019.8.0.
network
low complexity
deskpro CWE-862
7.5
2020-03-27 CVE-2020-10955 Missing Authorization vulnerability in multiple products
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
network
low complexity
gitlab debian CWE-862
6.5
2020-03-24 CVE-2019-20614 Missing Authorization vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software.
network
low complexity
google CWE-862
7.5
2020-03-24 CVE-2019-20609 Missing Authorization vulnerability in Google Android 9.0
An issue was discovered on Samsung mobile devices with P(9.0) software.
low complexity
google CWE-862
6.5
2020-03-24 CVE-2019-20599 Missing Authorization vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software.
network
low complexity
google CWE-862
7.5
2020-03-24 CVE-2019-20555 Missing Authorization vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x) software.
network
low complexity
google CWE-862
5.3
2020-03-24 CVE-2020-10684 Missing Authorization vulnerability in multiple products
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean.
local
low complexity
redhat debian fedoraproject CWE-862
7.1
2020-03-20 CVE-2020-8139 Missing Authorization vulnerability in multiple products
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
network
low complexity
nextcloud fedoraproject CWE-862
6.5