VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 140 of 405
  • CVE-2025-45609HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45608HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

  • CVE-2025-45237HigMay 5, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file containing sensitive account information, including the encrypted password.

  • CVE-2025-46619HigApr 30, 2025
    risk 0.49cvss 7.6epss 0.00

    A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or…

  • CVE-2025-32470HigApr 28, 2025
    risk 0.49cvss 7.5epss 0.01

    A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availability of the device.

  • CVE-2025-30728HigApr 15, 2025
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2025-30707HigApr 15, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2025-29810HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.03

    Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-30140HigMar 18, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on G-Net Dashcam BB GONX devices. A Public Domain name is Used for the Internal Domain Name. It uses an unregistered public domain name as an internal domain, creating a security risk. This domain was not owned by GNET originally, allowing an attacker to…

  • CVE-2025-30141HigMar 18, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered on G-Net Dashcam BB GONX devices. One can Remotely Dump Video Footage and the Live Video Stream. It exposes API endpoints on ports 9091 and 9092 that allow remote access to recorded and live video feeds. An attacker who connects to the dashcam's network…

  • CVE-2025-25500HigMar 18, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers to deploy a contract without capability enforcement, and execute unauthorized actions on the…

  • CVE-2025-25381HigMar 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the KSRTC AWATAR app of Karnataka State Road Transport Corporation v1.3.0 allows to view sensitive information such as usernames and passwords.

  • CVE-2024-36259HigFeb 25, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.

  • CVE-2025-26616HigFeb 18, 2025
    risk 0.49cvss 7.5epss 0.01

    WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `exportar_dump.php` endpoint. This vulnerability could allow an attacker to gain unauthorized access to…

  • CVE-2024-56889HigFeb 6, 2025
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

  • CVE-2024-57433HigJan 31, 2025
    risk 0.49cvss 7.5epss 0.00

    macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state.

  • CVE-2025-24885HigJan 30, 2025
    risk 0.49cvss 7.6epss 0.00

    pwn.college is an education platform to learn about, and practice, core cybersecurity concepts in a hands-on fashion. Missing access control on rendering custom (unprivileged) dojo pages causes ability for users to create stored XSS.

  • CVE-2025-0745HigJan 30, 2025
    risk 0.49cvss 7.5epss 0.00

    An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the database by requesting the "/embedai/app/uploads/database/<SQL_FILE>" endpoint.

  • CVE-2025-0744HigJan 30, 2025
    risk 0.49cvss 7.5epss 0.00

    an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST request changing the parameters of the "/demos/embedai/pmt_cash_on_delivery/pay"…

  • CVE-2024-13240HigJan 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.