VYPR

CWE-280

Improper Handling of Insufficient Permissions or Privileges

BaseDraft

Description

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (176)

page 4 of 9
  • CVE-2023-2480HigMay 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications

  • CVE-2023-27087HigMar 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.

  • CVE-2022-2193HigJul 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via parameter tampering in the Device Manager page. This issue affects: HYPR Server versions prior to…

  • CVE-2025-29826HigMay 13, 2025
    risk 0.48cvss 7.3epss 0.01

    Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-21733HigApr 17, 2026
    risk 0.47cvss 7.3epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory reservation protections.

  • CVE-2022-25776HigSep 18, 2024
    risk 0.47cvss 8.3epss 0.00

    Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. Users could potentially access sensitive data such as names and surnames, company names and stage names.

  • CVE-2023-41972HigMar 26, 2024
    risk 0.47cvss 7.3epss 0.00

    In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.

  • CVE-2021-37851HigMay 11, 2022
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privileges. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0.…

  • CVE-2020-8219HigJul 30, 2020
    risk 0.47cvss 7.2epss 0.02

    An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.

  • CVE-2025-67848HigFeb 3, 2026
    risk 0.46cvss 8.1epss 0.00

    A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling…

  • CVE-2025-0468HigApr 4, 2025
    risk 0.46cvss 7.1epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages…

  • CVE-2024-12430HigJan 7, 2025
    risk 0.46cvss 7.0epss 0.00

    An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 version mentioned. After successfully exploiting CVE-2024-12429 (directory traversal), a successfully authenticated attacker can inject…

  • CVE-2023-0181HigApr 1, 2023
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.

  • CVE-2022-27167HigMay 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET,…

  • CVE-2022-22292HigFeb 11, 2022
    risk 0.46cvss 7.1epss 0.00

    Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

  • CVE-2021-38312HigSep 2, 2021
    risk 0.46cvss 7.1epss 0.01

    The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback`…

  • CVE-2020-29031HigFeb 15, 2021
    risk 0.46cvss 7.1epss 0.01

    An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to…

  • CVE-2020-17533HigDec 29, 2020
    risk 0.46cvss 8.1epss 0.04

    Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy enforcement functions before permitting an authenticated user to perform certain administrative operations. Specifically, the return values of the 'canFlush' and…

  • CVE-2026-20448MedMay 4, 2026
    risk 0.44cvss 6.7epss 0.00

    In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513;…

  • CVE-2025-3931HigMay 14, 2025
    risk 0.44cvss 7.8epss 0.00

    A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and…