VYPR

CWE-280

Improper Handling of Insufficient Permissions or Privileges

BaseDraft

Description

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (166)

page 4 of 9
  • CVE-2023-41972HigMar 26, 2024
    risk 0.47cvss 7.3epss 0.00

    In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later.

  • CVE-2021-37851HigMay 11, 2022
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privileges. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0.…

  • CVE-2020-8219HigJul 30, 2020
    risk 0.47cvss 7.2epss 0.02

    An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.

  • CVE-2025-67848HigFeb 3, 2026
    risk 0.46cvss 8.1epss 0.00

    A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling…

  • CVE-2025-0468HigApr 4, 2025
    risk 0.46cvss 7.1epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages…

  • CVE-2024-12430HigJan 7, 2025
    risk 0.46cvss 7.0epss 0.00

    An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 version mentioned. After successfully exploiting CVE-2024-12429 (directory traversal), a successfully authenticated attacker can inject…

  • CVE-2023-0181HigApr 1, 2023
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.

  • CVE-2022-27167HigMay 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET,…

  • CVE-2022-22292HigFeb 11, 2022
    risk 0.46cvss 7.1epss 0.00

    Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

  • CVE-2021-38312HigSep 2, 2021
    risk 0.46cvss 7.1epss 0.01

    The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”. The `permissions_callback`…

  • CVE-2020-29031HigFeb 15, 2021
    risk 0.46cvss 7.1epss 0.01

    An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges. This issue affects all GateManager versions prior to…

  • CVE-2020-17533HigDec 29, 2020
    risk 0.46cvss 8.1epss 0.04

    Apache Accumulo versions 1.5.0 through 1.10.0 and version 2.0.0 do not properly check the return value of some policy enforcement functions before permitting an authenticated user to perform certain administrative operations. Specifically, the return values of the 'canFlush' and…

  • CVE-2026-20448MedMay 4, 2026
    risk 0.44cvss 6.7epss 0.00

    In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513;…

  • CVE-2025-3931HigMay 14, 2025
    risk 0.44cvss 7.8epss 0.00

    A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and…

  • CVE-2024-8315MedMar 25, 2025
    risk 0.44cvss epss 0.00

    An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated local attacker to read credential information.

  • CVE-2025-27521MedMar 4, 2025
    risk 0.44cvss 6.8epss 0.00

    Vulnerability of improper access permission in the process management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-32489MedAug 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, to bypass mode protections and gain elevated privileges.  

  • CVE-2022-21363MedJan 19, 2022
    risk 0.43cvss 6.6epss 0.01

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2020-3427MedOct 14, 2020
    risk 0.43cvss 6.6epss 0.00

    The Windows Logon installer prior to 4.1.2 did not properly validate file installation paths. This allows an attacker with local user privileges to coerce the installer to write to arbitrary privileged directories. If successful, an attacker can manipulate files used by Windows…

  • CVE-2026-73239MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.