VYPR

CWE-280

Improper Handling of Insufficient Permissions or Privileges

BaseDraft

Description

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (166)

page 3 of 9
  • CVE-2023-25543HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system.

  • CVE-2023-43591HigNov 15, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper privilege management in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2019-17437HigDec 5, 2019
    risk 0.51cvss 7.8epss 0.00

    An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser custom role user to elevate privileges and become superuser. This issue affects PAN-OS 7.1 versions prior to 7.1.25; 8.0 versions prior to 8.0.20; 8.1 versions…

  • CVE-2026-18860HigAug 11, 2026
    risk 0.50cvss 8.7epss 0.00

    Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines…

  • CVE-2026-24096HigApr 1, 2026
    risk 0.50cvss 8.8epss 0.00

    Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive information

  • CVE-2024-6660HigJul 17, 2024
    risk 0.50cvss 8.8epss 0.01

    The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the bookingpress_import_data_continue_process_f…

  • CVE-2026-6805HigMay 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve information from the server allowing an offline brute-force attack of the access code associated to this sharing link.

  • CVE-2025-58410HigNov 17, 2025
    risk 0.49cvss 7.5epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by improper handling of the memory protections for the buffer resource.

  • CVE-2025-45376HigSep 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Dell Repository Manager (DRM), versions 3.4.7 and 3.4.8, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2025-46740HigMay 12, 2025
    risk 0.49cvss 7.5epss 0.00

    An authenticated user without user administrative permissions could change the administrator Account Name.

  • CVE-2024-8451HigSep 30, 2024
    risk 0.49cvss 7.5epss 0.01

    Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the…

  • CVE-2023-52537HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-30418HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-25844HigMar 3, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.

  • CVE-2023-2480HigMay 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications

  • CVE-2023-27087HigMar 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.

  • CVE-2022-2193HigJul 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page. This issue affects: HYPR Server versions prior to…

  • CVE-2025-29826HigMay 13, 2025
    risk 0.48cvss 7.3epss 0.01

    Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-21733HigApr 17, 2026
    risk 0.47cvss 7.3epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory reservation protections.

  • CVE-2022-25776HigSep 18, 2024
    risk 0.47cvss 8.3epss 0.00

    Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names.