VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 137 of 405
  • CVE-2025-63664HigDec 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access other users' message history with AI agents.

  • CVE-2025-63663HigDec 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the /api/v1/conversations/*/files API of GT Edge AI Platform before v2.0.10 allows unauthorized attackers to access other users' uploaded files.

  • CVE-2025-65176HigDec 15, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a machine where OneAgent is installed and receiving a "STATUS_LOGON_FAILURE" error, the agent will retrieve every user token on the machine and repeatedly attempt…

  • CVE-2025-24857HigDec 10, 2025
    risk 0.49cvss 7.6epss 0.00

    Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code.

  • CVE-2025-63363HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.002880.0301 allows attackers to execute de-authentication attacks, allowing crafted deauthentication and disassociation…

  • CVE-2025-57213HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via a crafted request.

  • CVE-2025-57212HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive information via a crafted request.

  • CVE-2025-57210HigDec 4, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive information via unspecified vectors.

  • CVE-2025-55471HigNov 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.

  • CVE-2025-46175HigNov 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.

  • CVE-2025-46174HigNov 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.

  • CVE-2025-54563HigNov 24, 2025
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows Incorrect Access Control, leading to Remote Information Disclosure.

  • CVE-2025-54338HigNov 24, 2025
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attacker to disclose user hashes.

  • CVE-2025-63219HigNov 19, 2025
    risk 0.49cvss 7.5epss 0.00

    The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify…

  • CVE-2025-41737HigNov 18, 2025
    risk 0.49cvss 7.5epss 0.00

    Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.

  • CVE-2025-63667HigNov 12, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attackers to access sensitive API endpoints without authentication.

  • CVE-2025-64110HigNov 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agent to read sensitive files that should be protected via cursorignore. An attacker who has already achieved prompt injection, or a malicious model, could create…

  • CVE-2025-43502HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, visionOS 26.1. An app may be able to bypass certain Privacy preferences.

  • CVE-2025-43454HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. A device may persistently fail to lock.

  • CVE-2025-43450HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An app may be able to learn information about the current camera view before being granted camera access.