Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-03-06 CVE-2020-9457 Missing Authorization vulnerability in Metagauss Registrationmagic
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.
network
low complexity
metagauss CWE-862
8.8
2020-03-06 CVE-2020-9456 Missing Authorization vulnerability in Metagauss Registrationmagic
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.
network
low complexity
metagauss CWE-862
8.8
2020-03-06 CVE-2020-9455 Missing Authorization vulnerability in Metagauss Registrationmagic
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php send_email_user_view.
network
low complexity
metagauss CWE-862
4.3
2020-02-26 CVE-2019-19989 Missing Authorization vulnerability in Seling Visual Access Manager 4.15.0/4.29.0
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29.
network
low complexity
seling CWE-862
7.5
2020-02-19 CVE-2012-0055 Missing Authorization vulnerability in multiple products
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.
local
low complexity
linux canonical CWE-862
7.8
2020-02-19 CVE-2012-6614 Missing Authorization vulnerability in Dlink Dsr-250N Firmware
D-Link DSR-250N devices before 1.08B31 allow remote authenticated users to obtain "persistent root access" via the BusyBox CLI, as demonstrated by overwriting the super user password.
network
low complexity
dlink CWE-862
7.2
2020-02-18 CVE-2013-4226 Missing Authorization vulnerability in Drupal Authenticated User Page Caching
The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.
network
low complexity
drupal CWE-862
6.5
2020-02-13 CVE-2020-0023 Missing Authorization vulnerability in Google Android 10.0
In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check.
local
low complexity
google CWE-862
5.5
2020-02-12 CVE-2020-6188 Missing Authorization vulnerability in SAP ERP and S/4 Hana
VAT Pro-Rata reports in SAP ERP (SAP_APPL versions 600, 602, 603, 604, 605, 606, 616 and SAP_FIN versions 617, 618, 700, 720, 730) and SAP S/4 HANA (versions 100, 101, 102, 103, 104) do not perform necessary authorization checks for an authenticated user leading to Missing Authorization Check.
network
low complexity
sap CWE-862
8.8
2020-02-12 CVE-2020-6183 Missing Authorization vulnerability in SAP Host Agent 7.21
SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive responses that may contain data read with user root privileges e.g.
network
low complexity
sap CWE-862
6.5