VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 156 of 405
  • CVE-2025-55012HigAug 11, 2025
    risk 0.48cvss —epss 0.00

    Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by bypassing user permission checks. An AI Agent could have exploited a permissions bypass vulnerability to create or modify a…

  • CVE-2025-4468HigMay 9, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-photo.php. The manipulation of the argument userImage leads to unrestricted upload. The attack may be…

  • CVE-2025-46628HigMay 1, 2025
    risk 0.48cvss 7.3epss 0.01

    Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain root shell access to the device by sending a crafted UDP packet to the 'ate' service when it is enabled. Authentication is not…

  • CVE-2025-30736HigApr 15, 2025
    risk 0.48cvss 7.4epss 0.00

    Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM.…

  • CVE-2025-21587HigApr 15, 2025
    risk 0.48cvss 7.4epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE:8u441, 8u441-perf, 11.0.26, 17.0.14, 21.0.6, 24; Oracle GraalVM for JDK:17.0.14,…

  • CVE-2025-23389HigApr 11, 2025
    risk 0.48cvss 8.4epss 0.00

    A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.

  • CVE-2025-29804HigApr 8, 2025
    risk 0.48cvss 7.3epss 0.01

    Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

  • CVE-2025-30460HigMar 31, 2025
    risk 0.48cvss 7.4epss 0.01

    A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

  • CVE-2025-24229HigMar 31, 2025
    risk 0.48cvss 7.4epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A sandboxed app may be able to access sensitive user data.

  • CVE-2024-53348HigMar 21, 2025
    risk 0.48cvss 7.4epss 0.00

    LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive information and escalate privileges.

  • CVE-2025-23242HigMar 11, 2025
    risk 0.48cvss 7.3epss 0.02

    NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, or information disclosure.

  • CVE-2025-24994HigMar 11, 2025
    risk 0.48cvss 7.3epss 0.01

    Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

  • CVE-2025-1555HigFeb 21, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-1355HigFeb 16, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signup.php of the component Add Picture. The manipulation leads to unrestricted upload. The attack can be…

  • CVE-2025-24042HigFeb 11, 2025
    risk 0.48cvss 7.3epss 0.01

    Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability

  • CVE-2024-13030HigDec 30, 2024
    risk 0.48cvss 7.3epss 0.02

    A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the function SetAutoRebootSettings/SetClientInfo/SetDMZSettings/SetFirewallSettings/SetParentsControlInfo/SetQoSSettings/SetVirtualServerSettings of the file /HNAP1/…

  • CVE-2024-49107HigDec 12, 2024
    risk 0.48cvss 7.3epss 0.02

    WmsRepair Service Elevation of Privilege Vulnerability

  • CVE-2024-43594HigDec 12, 2024
    risk 0.48cvss 7.3epss 0.02

    Microsoft System Center Elevation of Privilege Vulnerability

  • CVE-2024-12233HigDec 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted…

  • CVE-2023-51644HigNov 22, 2024
    risk 0.48cvss 7.3epss 0.02

    Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw…