VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 138 of 405
  • CVE-2025-43413HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.01

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A sandboxed app may be able to observe system-wide network…

  • CVE-2025-63423HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 was discovered to store the Administrator password.

  • CVE-2025-63422HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the Web management interface in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to arbitrarily change the administrator username and password via sending a crafted GET request.

  • CVE-2025-61120HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    AG Life Logger Android App version v1.0.2.72 and before (package name com.donki.healthy), developed by IO FIT, K.K., contains improper access control vulnerabilities. Exposed credentials in traffic may allow attackers to misuse cloud resources, and predictable verification codes…

  • CVE-2025-61119HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access control vulnerabilities. Attackers may gain unauthorized access to user details and obtain group information, including entry codes, by manipulating API request…

  • CVE-2025-61114HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    2nd Line Android App version v1.2.92 and before (package name com.mysecondline.app), developed by AutoBizLine, Inc., contains an improper access control vulnerability in its authentication mechanism. The server only validates the first character of the user_token, enabling…

  • CVE-2025-61118HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    mCarFix Motorists App version 2.3 (package name com.skytop.mcarfix), developed by Paniel Mwaura, contains improper access control vulnerabilities. Attackers may bypass verification to arbitrarily register accounts, and by tampering with sequential numeric IDs, gain unauthorized…

  • CVE-2025-61117HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Senza: Keto & Fasting Android App version 2.10.15 (package name com.gl.senza), developed by Paul Itoi, contains an improper access control vulnerability. By exploiting insufficient checks in user data API endpoints, attackers can obtain authentication tokens and perform account…

  • CVE-2025-61116HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    AdForest - Classified Android App version 4.0.12 (package name scriptsbundle.adforest), developed by Muhammad Jawad Arshad, contains an improper access control vulnerability in its authentication mechanism. The app uses a Base64-encoded email address as the authorization…

  • CVE-2025-61115HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    ABC Fine Wine & Spirits Android App version v.11.27.5 and before (package name com.cta.abcfinewineandspirits), developed by ABC Liquors, Inc., contains an improper access control vulnerability in its login mechanism. The application does not properly validate user passwords…

  • CVE-2025-61113HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    TalkTalk 3.3.6 Android App contains improper access control vulnerabilities in multiple API endpoints. By modifying request parameters, attackers may obtain sensitive user information (such as device identifiers and birthdays) and access private group information, including join…

  • CVE-2025-61234HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control on Dataphone A920 v2025.07.161103 exposes a service on port 8888 by default on the local network without authentication. This allows an attacker to interact with the device via a TCP socket without credentials. Additionally, sending an HTTP request to…

  • CVE-2025-60800HigOct 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

  • CVE-2025-60354HigOct 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot.

  • CVE-2025-61760HigOct 21, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM…

  • CVE-2025-58726HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-48707HigSep 25, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in some HA use cases, be shared among administrators, which can cause secret sharing.

  • CVE-2025-56241HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.07

    Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator password via a crafted POST request to sysAccess.asp. This allows full administrative control of the router without authentication.

  • CVE-2025-48869HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded resume files in Horilla 1.3.0 by directly guessing or predicting file URLs. These files are stored in a publicly accessible directory, allowing attackers to…

  • CVE-2025-23329HigSep 17, 2025
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause memory corruption by identifying and accessing the shared memory region used by the Python backend. A successful exploit of this vulnerability might lead to denial of…