VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 244 of 406
  • CVE-2025-60799MedNov 20, 2025
    risk 0.40cvss 6.1epss 0.00

    phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The application allows unauthorized manipulation of session variables by accepting user-controlled parameters ('subject', 'server', 'database', 'queryid') without proper…

  • CVE-2025-43414MedNov 4, 2025
    risk 0.40cvss 6.2epss 0.00

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. A shortcut may be able to access files that are normally inaccessible to the Shortcuts app.

  • CVE-2025-62713HigOct 23, 2025
    risk 0.40cvss —epss 0.01

    Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running in development mode. This affects development mode only, production deployments were never affected.…

  • CVE-2025-53060MedOct 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2025-53058MedOct 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Application Logging Interfaces). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2025-53052MedOct 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2025-53041MedOct 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. …

  • CVE-2025-50107MedJul 15, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Request handling). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2025-30759MedJul 15, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2025-45083MedJul 1, 2025
    risk 0.40cvss 6.1epss 0.00

    Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental pin feature via unspecified vectors.

  • CVE-2025-30732MedApr 15, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2025-30709MedApr 15, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-54565MedMar 17, 2025
    risk 0.40cvss 6.2epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access sensitive user data.

  • CVE-2025-1390MedFeb 18, 2025
    risk 0.40cvss 6.1epss 0.00

    The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability…

  • CVE-2025-21202MedJan 14, 2025
    risk 0.40cvss 6.1epss 0.01

    Windows Recovery Environment Agent Elevation of Privilege Vulnerability

  • CVE-2024-8269HigSep 13, 2024
    risk 0.40cvss 7.3epss 0.00

    The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user…

  • CVE-2024-21150MedJul 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-30059MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.01

    Microsoft Intune for Android Mobile Application Management Tampering Vulnerability

  • CVE-2024-33393MedMay 1, 2024
    risk 0.40cvss 6.2epss 0.00

    An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

  • CVE-2024-28917MedApr 9, 2024
    risk 0.40cvss 6.2epss 0.01

    Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability