VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 300 of 406
  • CVE-2025-3169MedApr 3, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in Projeqtor up to 12.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tool/saveAttachment.php. The manipulation of the argument attachmentFiles leads to unrestricted upload. The attack may be…

  • CVE-2025-24248MedMar 31, 2025
    risk 0.33cvss 5.0epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to enumerate devices that have signed into the user's Apple Account.

  • CVE-2025-1882MedMar 3, 2025
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in i-Drive i11 and i12 up to 20250227. It has been rated as critical. Affected by this issue is some unknown functionality of the component Device Setting Handler. The manipulation leads to improper access control for register interface. The attack…

  • CVE-2023-52164MedFeb 3, 2025
    risk 0.33cvss 5.1epss 0.00

    access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2020-36831MedOct 16, 2024
    risk 0.33cvss 5.0epss 0.01

    The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged…

  • CVE-2024-28050MedAug 14, 2024
    risk 0.33cvss 5.0epss 0.00

    Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2024-36505MedAug 13, 2024
    risk 0.33cvss 5.1epss 0.00

    An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has already successfully obtained write access to the underlying system (via another hypothetical exploit) to bypass…

  • CVE-2024-33260MedApr 26, 2024
    risk 0.33cvss 5.1epss 0.00

    Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at jerry-core/parser/js/js-parser-expr.c

  • CVE-2024-20325MedFeb 21, 2024
    risk 0.33cvss 5.1epss 0.00

    A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access…

  • CVE-2023-28715MedFeb 14, 2024
    risk 0.33cvss 5.0epss 0.00

    Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-26585MedFeb 14, 2024
    risk 0.33cvss 5.0epss 0.00

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-32064MedNov 28, 2023
    risk 0.33cvss 5.0epss 0.01

    OroCommerce package with customer portal and non authenticated visitor website base features. Back-office users can access information about Customer and Customer User menus, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in…

  • CVE-2023-32609MedAug 11, 2023
    risk 0.33cvss 5.0epss 0.00

    Improper access control in the Intel Unite(R) android application before version 4.2.3504 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-46279MedMay 10, 2023
    risk 0.33cvss 5.0epss 0.00

    Improper access control in the Intel(R) Retail Edge android application before version 3.0.301126-RELEASE may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2023-29513MedApr 19, 2023
    risk 0.33cvss 5.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. If guest has view right on any document. It's possible to create a new user using the `distribution/firstadminuser.wiki` in the wrong context. This vulnerability has been…

  • CVE-2022-39875MedOct 7, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

  • CVE-2022-39855MedOct 7, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.

  • CVE-2022-33731MedAug 5, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

  • CVE-2022-28780MedMay 3, 2022
    risk 0.33cvss 5.0epss 0.00

    Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.

  • CVE-2022-28775MedApr 11, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.