VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 273 of 327
  • CVE-2019-5452LowJul 30, 2019
    risk 0.16cvss 2.4epss 0.00

    Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved.

  • CVE-2015-7473LowJun 26, 2016
    risk 0.16cvss 2.5epss 0.00

    runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restrictions by leveraging authority for +connect and +dsp.

  • CVE-2026-42158LowMay 12, 2026
    risk 0.15cvss epss 0.00

    Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, an adversary with knowledge of an investigation ID, could update the metadata of an investigation of another user. This vulnerability…

  • CVE-2026-35250LowApr 21, 2026
    risk 0.15cvss 2.3epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes…

  • CVE-2026-35402LowApr 17, 2026
    risk 0.15cvss epss 0.00

    mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the read_only mode enforcement can be bypassed using APOC CALL procedures, potentially allowing unauthorized write operations or server-side request forgery. This…

  • CVE-2022-39906LowDec 8, 2022
    risk 0.15cvss 2.3epss 0.00

    Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.

  • CVE-2026-19245LowAug 7, 2026
    risk 0.14cvss 3.3epss 0.00

    A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component Login-shell Environment Handler. Executing a manipulation can lead to information disclosure. The attack…

  • CVE-2026-60190LowJul 21, 2026
    risk 0.14cvss 2.2epss 0.00

    Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit…

  • CVE-2025-6592LowFeb 2, 2026
    risk 0.14cvss epss 0.00

    Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects AbuseFilter: from fe0b1cb9e9691faf4d8d9bd80646589f6ec37615 before 1.43.2, 1.44.0.

  • CVE-2025-24314LowNov 11, 2025
    risk 0.14cvss 2.2epss 0.00

    Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable data exposure.…

  • CVE-2024-29206LowMay 7, 2024
    risk 0.14cvss 2.2epss 0.00

    An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV Station Pro…

  • CVE-2023-5549LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

  • CVE-2023-5542LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Students in "Only see own membership" groups could see other students in the group, which should be hidden.

  • CVE-2023-21438LowFeb 9, 2023
    risk 0.14cvss 2.1epss 0.00

    Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.

  • CVE-2022-24924LowFeb 11, 2022
    risk 0.14cvss 2.2epss 0.01

    An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

  • CVE-2026-11464LowJun 7, 2026
    risk 0.13cvss 3.1epss 0.00

    A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipulation of the argument salt…

  • CVE-2026-33212LowApr 15, 2026
    risk 0.13cvss 3.1epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker needs to brute-force the random UUID of…

  • CVE-2026-1407LowJan 25, 2026
    risk 0.13cvss 2.0epss 0.00

    A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the component UART Interface. Performing a manipulation results in information disclosure. The attack may be carried out on the physical device. The attack is…

  • CVE-2025-13870LowDec 2, 2025
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards…

  • CVE-2025-32037LowNov 11, 2025
    risk 0.13cvss 2.0epss 0.00

    Improper access control for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow a denial of service. Network adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially…