VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 180 of 406
  • CVE-2025-14977HigJan 20, 2026
    risk 0.46cvss 8.1epss 0.00

    The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to…

  • CVE-2025-69220HigJan 7, 2026
    risk 0.46cvss 7.1epss 0.00

    LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by…

  • CVE-2025-66736HigDec 22, 2025
    risk 0.46cvss 7.1epss 0.00

    youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an…

  • CVE-2025-11901HigDec 17, 2025
    risk 0.46cvss —epss 0.00

    An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a…

  • CVE-2025-62570HigDec 9, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper access control in Windows Camera Frame Server Monitor allows an authorized attacker to disclose information locally.

  • CVE-2025-66028HigNov 26, 2025
    risk 0.46cvss 8.2epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable to privilege escalation via Login Response Manipulation. During the login process, the server response included a parameter called isMasterAdmin. By…

  • CVE-2025-56219HigOct 20, 2025
    risk 0.46cvss 7.1epss 0.00

    Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user accounts are created.

  • CVE-2025-61543HigOct 16, 2025
    risk 0.46cvss 7.1epss 0.00

    A Host Header Injection vulnerability exists in the password reset functionality of CraftMyCMS 4.0.2.2. The system uses `$_SERVER['HTTP_HOST']` directly to construct password reset links sent via email. An attacker can manipulate the Host header to send malicious reset links,…

  • CVE-2025-61541HigOct 16, 2025
    risk 0.46cvss 7.1epss 0.00

    Webmin 2.510 is vulnerable to a Host Header Injection in the password reset functionality (forgot_send.cgi). The reset link sent to users is constructed using the HTTP Host header via get_webmin_email_url(). An attacker can manipulate the Host header to inject a malicious domain…

  • CVE-2025-47989HigOct 14, 2025
    risk 0.46cvss 7.0epss 0.01

    Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59943HigOct 3, 2025
    risk 0.46cvss 8.1epss 0.00

    phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is often used as an identifier…

  • CVE-2025-43263HigSep 15, 2025
    risk 0.46cvss 7.1epss 0.00

    The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.

  • CVE-2025-55741HigAug 22, 2025
    risk 0.46cvss 8.1epss 0.00

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete privilege for products are unable to delete individual products via the standard endpoint, as expected. However, these…

  • CVE-2025-53003HigJul 1, 2025
    risk 0.46cvss —epss 0.00

    The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without scope verification. This has a large internal surface attack area that exposes all sorts of information from the IDP including…

  • CVE-2025-24916HigMay 23, 2025
    risk 0.46cvss 7.0epss 0.00

    When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories…

  • CVE-2025-29973HigMay 13, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

  • CVE-2025-31232HigMay 12, 2025
    risk 0.46cvss 7.1epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. A sandboxed app may be able to access sensitive user data.

  • CVE-2025-46635HigMay 1, 2025
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces on the router allows an attacker (who is authenticated to the guest Wi-Fi) to access resources on the router and/or resources and…

  • CVE-2024-54533HigMar 31, 2025
    risk 0.46cvss 7.0epss 0.01

    A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access sensitive user data.

  • CVE-2024-49049HigNov 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Visual Studio Code Remote Extension Elevation of Privilege Vulnerability