VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 312 of 327
  • CVE-2025-43862HigApr 25, 2025
    risk 0.00cvss 7.6epss 0.00

    Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allows non-admin users to make…

  • CVE-2025-32796MedApr 18, 2025
    risk 0.00cvss 6.5epss 0.00

    Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the API, even though the web UI button for this action is disabled and normal users are not permitted to…

  • CVE-2025-32795MedApr 18, 2025
    risk 0.00cvss 6.5epss 0.00

    Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows non-admin users to modify app…

  • CVE-2025-32790MedApr 18, 2025
    risk 0.00cvss 6.3epss 0.00

    Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in '/export' should only allow administrator users to export DSL.…

  • CVE-2025-31494LowApr 15, 2025
    risk 0.00cvss 3.5epss 0.00

    AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. The AutoGPT Platform's WebSocket API transmitted node execution updates to subscribers based on the graph_id+graph_version.…

  • CVE-2025-27140CriFeb 24, 2025
    risk 0.00cvss 9.8epss 0.03

    WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely. The command…

  • CVE-2024-12478MedDec 16, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the file /index.php/upload/upload_file/1/1. The manipulation of the argument file leads to unrestricted upload. The attack can be…

  • CVE-2024-52514MedNov 15, 2024
    risk 0.00cvss 4.1epss 0.00

    Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder inside Nextcloud allowing them to afterwards potentially access…

  • CVE-2024-52509LowNov 15, 2024
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and then downloading it from…

  • CVE-2024-10965MedNov 7, 2024
    risk 0.00cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. The attack can be launched…

  • CVE-2024-48925NonOct 22, 2024
    risk 0.00cvss 0.0epss 0.00

    Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. The issue allows low-privilege users to access the webhook API and retrieve information that should be restricted to users…

  • CVE-2024-45397MedOct 11, 2024
    risk 0.00cvss 5.9epss 0.00

    h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the IP-address-based access control is used, the access control does not detect and prohibit HTTP…

  • CVE-2024-45313MedSep 2, 2024
    risk 0.00cvss 5.4epss 0.00

    Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-compose.yml from before 2024-08-28, the configuration for LaTeX compiles was insecure by default, requiring the administrator to…

  • CVE-2024-45522CriSep 2, 2024
    risk 0.00cvss 9.8epss 0.01

    Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.

  • CVE-2024-41703CriJul 22, 2024
    risk 0.00cvss 9.8epss 0.00

    LibreChat through 0.7.4-rc1 has incorrect access control for message updates.

  • CVE-2024-37887LowJun 14, 2024
    risk 0.00cvss 3.5epss 0.00

    Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to…

  • CVE-2024-37884LowJun 14, 2024
    risk 0.00cvss 3.5epss 0.00

    Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3 and that the…

  • CVE-2024-37883MedJun 14, 2024
    risk 0.00cvss 4.3epss 0.00

    Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted cards. It is recommended that the…

  • CVE-2024-37882HigJun 14, 2024
    risk 0.00cvss 8.1epss 0.01

    Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise…

  • CVE-2024-37317MedJun 14, 2024
    risk 0.00cvss 4.6epss 0.00

    The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the…