VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 20 of 404
  • CVE-2025-25962CriApr 29, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function

  • CVE-2025-28229CriApr 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.

  • CVE-2025-28413CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

  • CVE-2025-28412CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

  • CVE-2025-28411CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

  • CVE-2025-28410CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges

  • CVE-2025-28408CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter

  • CVE-2025-28406CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter

  • CVE-2025-28405CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method

  • CVE-2025-28402CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter

  • CVE-2025-30462CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Apps that appear to use App Sandbox may be able to launch without restrictions.

  • CVE-2025-30433CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. A shortcut may be able to access files that are normally…

  • CVE-2025-24259CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.

  • CVE-2025-24241CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to trick a user into copying sensitive data to the pasteboard.

  • CVE-2025-26010CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.

  • CVE-2025-29315CriMar 24, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to execute privileged operations via a crafted request.

  • CVE-2024-53351CriMar 21, 2025
    risk 0.64cvss 9.8epss 0.00

    Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.

  • CVE-2023-47539CriMar 18, 2025
    risk 0.64cvss 9.8epss 0.01

    An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request.

  • CVE-2025-27649CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.893 Application 20.0.2140 allows Incorrect Access Control: PHP V-2023-016.

  • CVE-2025-27646CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Edit User Account Exposure V-2024-001.