Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2023-12-04 CVE-2023-42747 Missing Authorization vulnerability in Google Android 11.0/12.0/13.0
In camera service, there is a possible missing permission check.
local
low complexity
google CWE-862
7.8
2023-12-04 CVE-2023-42748 Missing Authorization vulnerability in Google Android 11.0/12.0/13.0
In telecom service, there is a possible missing permission check.
local
low complexity
google CWE-862
7.8
2023-12-04 CVE-2023-42749 Missing Authorization vulnerability in Google Android 11.0/12.0/13.0
In enginnermode service, there is a possible way to write permission usage records of an app due to a missing permission check.
local
low complexity
google CWE-862
5.5
2023-11-30 CVE-2023-37890 Missing Authorization vulnerability in Liquidweb KB Support
Missing Authorization vulnerability in WPOmnia KB Support – WordPress Help Desk and Knowledge Base allows Accessing Functionality Not Properly Constrained by ACLs. Users with a role as low as a subscriber can view other customers.This issue affects KB Support – WordPress Help Desk and Knowledge Base: from n/a through 1.5.88.
network
low complexity
liquidweb CWE-862
4.3
2023-11-29 CVE-2023-49652 Missing Authorization vulnerability in Jenkins Google Compute Engine
Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins and to connect to Google Cloud Platform using attacker-specified credentials IDs obtained through another method, to obtain information about existing projects.
network
low complexity
jenkins CWE-862
2.7
2023-11-29 CVE-2023-49654 Missing Authorization vulnerability in Jenkins Matlab 2.11.0
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.
network
low complexity
jenkins CWE-862
critical
9.8
2023-11-29 CVE-2023-49674 Missing Authorization vulnerability in Jenkins Neuvector vulnerability Scanner
A missing permission check in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.
network
low complexity
jenkins CWE-862
4.3
2023-11-27 CVE-2023-5525 Missing Authorization vulnerability in Limitloginattempts Limit Login Attempts Reloaded
The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.
network
low complexity
limitloginattempts CWE-862
4.3
2023-11-27 CVE-2023-5611 Missing Authorization vulnerability in Seraphinitesolutions Seraphinite Accelerator
The Seraphinite Accelerator WordPress plugin before 2.20.32 does not have authorisation and CSRF checks when resetting and importing its settings, allowing unauthenticated users to reset them
network
low complexity
seraphinitesolutions CWE-862
5.3
2023-11-27 CVE-2023-5737 Missing Authorization vulnerability in Webtoffee Backup and Migration
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.
network
low complexity
webtoffee CWE-862
4.3