Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-04-16 CVE-2019-14116 Missing Authorization vulnerability in Qualcomm Ipq6018 Firmware
Privilege escalation by using an altered debug policy image can occur as the XPU protecting the debug policy regions are disabled during the crash dump boot flow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018
local
low complexity
qualcomm CWE-862
7.8
2020-04-15 CVE-2019-20676 Missing Authorization vulnerability in Netgear products
Certain NETGEAR devices are affected by lack of access control at the function level.
local
low complexity
netgear CWE-862
6.0
2020-04-15 CVE-2020-7278 Missing Authorization vulnerability in Mcafee Endpoint Security
Exploiting incorrectly configured access control security levels vulnerability in ENS Firewall in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 and 10.6.1 April 2020 updates allows remote attackers and local users to allow or block unauthorized traffic via pre-existing rules not being handled correctly when updating to the February 2020 updates.
network
low complexity
mcafee CWE-862
6.5
2020-04-14 CVE-2020-6233 Missing Authorization vulnerability in SAP products
SAP S/4 HANA (Financial Products Subledger and Banking Services), versions - FSAPPL 400, 450, 500 and S4FPSL 100, allows an authenticated user to run an analysis report due to Missing Authorization Check, resulting in slowing the system.
network
low complexity
sap CWE-862
4.3
2020-04-14 CVE-2020-6232 Missing Authorization vulnerability in SAP Commerce Cloud 1811/1905
SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check.
network
low complexity
sap CWE-862
5.3
2020-04-08 CVE-2018-21047 Missing Authorization vulnerability in Google Android 8.0/8.1
An issue was discovered on Samsung mobile devices with O(8.x) software.
network
low complexity
google CWE-862
7.5
2020-04-08 CVE-2018-21046 Missing Authorization vulnerability in Google Android 8.0/8.1
An issue was discovered on Samsung mobile devices with O(8.x) software.
low complexity
google CWE-862
2.4
2020-04-08 CVE-2018-21042 Missing Authorization vulnerability in Google Android
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software.
network
low complexity
google CWE-862
critical
9.8
2020-04-07 CVE-2020-9514 Missing Authorization vulnerability in Idxbroker Impress for IDX Broker
An issue was discovered in the IMPress for IDX Broker plugin before 2.6.2 for WordPress.
network
low complexity
idxbroker CWE-862
6.5
2020-04-07 CVE-2020-11514 Missing Authorization vulnerability in Rankmath SEO
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
network
low complexity
rankmath CWE-862
critical
9.8