Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2023-08-22 CVE-2020-23793 Missing Authorization vulnerability in Spice-Space Spice-Server 0.14.06El76.1
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product.
network
low complexity
spice-space CWE-862
8.6
2023-08-21 CVE-2023-4302 Missing Authorization vulnerability in Jenkins Fortify
A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2023-08-16 CVE-2023-40344 Missing Authorization vulnerability in Jenkins Delphix
A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2023-08-16 CVE-2023-39507 Missing Authorization vulnerability in Recruit Rikunabi Next
Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver.
network
low complexity
recruit CWE-862
6.1
2023-08-14 CVE-2023-21234 Missing Authorization vulnerability in Google Android 11.0/13.0
In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check.
local
low complexity
google CWE-862
5.5
2023-08-14 CVE-2023-21288 Missing Authorization vulnerability in Google Android
In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check.
local
low complexity
google CWE-862
5.5
2023-08-14 CVE-2023-21132 Missing Authorization vulnerability in Google Android 12.0/12.1/13.0
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check.
low complexity
google CWE-862
6.8
2023-08-14 CVE-2023-21133 Missing Authorization vulnerability in Google Android 12.0/12.1/13.0
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check.
low complexity
google CWE-862
6.8
2023-08-14 CVE-2023-21134 Missing Authorization vulnerability in Google Android 12.0/12.1/13.0
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check.
low complexity
google CWE-862
6.8
2023-08-14 CVE-2023-21140 Missing Authorization vulnerability in Google Android 12.0/12.1/13.0
In onCreate of ManagePermissionsActivity.java, there is a possible way to bypass factory reset protections due to a missing permission check.
low complexity
google CWE-862
6.8