CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (10,117)
page 13 of 506| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-25282 | Cri | 0.64 | 9.8 | 0.00 | Sep 11, 2020 | An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September 2020). | ||
| CVE-2020-5368 | Cri | 0.64 | 9.8 | 0.02 | Jul 6, 2020 | Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form. | ||
| CVE-2018-21251 | Cri | 0.64 | 9.8 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body. | ||
| CVE-2020-10620 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2020 | Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely. | ||
| CVE-2020-6823 | Cri | 0.64 | 9.8 | 0.02 | Apr 24, 2020 | A malicious extension could have called browser.identity.launchWebAuthFlow, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75. | ||
| CVE-2020-11967 | Cri | 0.64 | 9.8 | 0.03 | Apr 21, 2020 | In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial… | ||
| CVE-2018-21042 | Cri | 0.64 | 9.8 | 0.01 | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code execution. The Samsung ID is SVE-2018-13299 (December 2018). | ||
| CVE-2020-11514 | Cri | 0.64 | 9.8 | 0.09 | Apr 7, 2020 | The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint. | ||
| CVE-2016-11036 | Cri | 0.64 | 9.8 | 0.00 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016). | ||
| CVE-2019-12498 | Cri | 0.64 | 9.8 | 0.02 | Mar 20, 2020 | The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism. | ||
| CVE-2020-10257 | Cri | 0.64 | 9.8 | 0.09 | Mar 10, 2020 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe… | ||
| CVE-2013-3960 | Cri | 0.64 | 9.9 | 0.02 | Jan 24, 2020 | Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass | ||
| CVE-2019-19899 | Cri | 0.64 | 9.8 | 0.01 | Dec 19, 2019 | Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature. | ||
| CVE-2019-15932 | Cri | 0.64 | 9.8 | 0.02 | Dec 12, 2019 | Intesync Solismed 3.3sp has Incorrect Access Control. | ||
| CVE-2019-13547 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2019 | Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication. | ||
| CVE-2019-1010152 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80. | ||
| CVE-2019-1010150 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php. | ||
| CVE-2019-1010149 | Cri | 0.64 | 9.8 | 0.02 | Jul 23, 2019 | zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php. | ||
| CVE-2019-6580 | Cri | 0.64 | 9.8 | 0.02 | Jun 12, 2019 | A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions <… | ||
| CVE-2018-4059 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2019 | An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can provide administrator access to the TURN… |
- risk 0.64cvss 9.8epss 0.00
An issue was discovered on LG mobile devices with Android OS 10 software. The lguicc software (for the LG Universal Integrated Circuit Card) allows attackers to bypass intended access restrictions on property values. The LG ID is LVE-SMP-200020 (September 2020).
- risk 0.64cvss 9.8epss 0.02
Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.
- risk 0.64cvss 9.8epss 0.01
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.
- risk 0.64cvss 9.8epss 0.02
A malicious extension could have called browser.identity.launchWebAuthFlow, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.
- risk 0.64cvss 9.8epss 0.03
In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code execution. The Samsung ID is SVE-2018-13299 (December 2018).
- risk 0.64cvss 9.8epss 0.09
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.
- risk 0.64cvss 9.8epss 0.00
An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).
- risk 0.64cvss 9.8epss 0.02
The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.
- risk 0.64cvss 9.8epss 0.09
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe…
- risk 0.64cvss 9.9epss 0.02
Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass
- risk 0.64cvss 9.8epss 0.01
Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature.
- risk 0.64cvss 9.8epss 0.02
Intesync Solismed 3.3sp has Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.03
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the IP address to use the function without authentication.
- risk 0.64cvss 9.8epss 0.02
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80.
- risk 0.64cvss 9.8epss 0.02
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: /user/zssave.php.
- risk 0.64cvss 9.8epss 0.02
zzcms version 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: zzcms File Delete to Code Execution. The component is: user/licence_save.php.
- risk 0.64cvss 9.8epss 0.02
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019 R1 (All versions <…
- risk 0.64cvss 9.8epss 0.02
An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticated telnet admin portal on the loopback interface. This can provide administrator access to the TURN…