VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,103)

page 321 of 406
  • CVE-2025-12297MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.java. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.

  • CVE-2025-12276MedOct 27, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation results in information disclosure. The attack can be executed remotely. The exploit is…

  • CVE-2025-62395MedOct 23, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

  • CVE-2025-53071MedOct 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2025-53064MedOct 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2025-48025MedOct 20, 2025
    risk 0.28cvss 4.3epss 0.00

    In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000, there is an improper access control vulnerability related to a log file.

  • CVE-2025-36636MedOct 8, 2025
    risk 0.28cvss 4.3epss 0.00

    In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope.

  • CVE-2025-11440MedOct 8, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Executing manipulation can lead to improper access controls. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This…

  • CVE-2025-11406MedOct 7, 2025
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in kaifangqian kaifangqian-base up to 7b3faecda13848b3ced6c17c7423b76c5b47b8ab. This issue affects the function getAllUsers of the file kaifangqian-parent/kaifangqian-system/src/main/java/com/kaifangqian/modules/system/controller/SysUserControl…

  • CVE-2025-36351MedSep 29, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.

  • CVE-2025-10607MedSep 17, 2025
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi. Such manipulation leads to information disclosure. The attack can be executed remotely. The exploit has been disclosed publicly…

  • CVE-2025-58751MedSep 8, 2025
    risk 0.28cvss 5.3epss 0.01

    Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network…

  • CVE-2025-9774MedSep 1, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patients/edit-patient.php. The manipulation of the argument Email leads to information disclosure. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-9461MedAug 26, 2025
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePackage/FilePackageManageAction.java of the component File Compression Handler. This manipulation of the argument idGroup causes…

  • CVE-2025-9240MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file /auth/info. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been released to the public and…

  • CVE-2025-50897MedAug 19, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly trigger a Store/AMO access fault during store instructions (sd).…

  • CVE-2025-9139MedAug 19, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Executing manipulation can lead to information disclosure. The attack may be performed from a remote…

  • CVE-2025-54397MedAug 7, 2025
    risk 0.28cvss 4.3epss 0.00

    Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.

  • CVE-2025-53112MedJul 30, 2025
    risk 0.28cvss 4.3epss 0.00

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions 9.1.0 through 10.0.18, a lack of permission checks can result in unauthorized removal of some specific resources. This is fixed…

  • CVE-2025-8226MedJul 27, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in yanyutao0402 ChanCMS up to 3.1.2. It has been classified as problematic. Affected is an unknown function of the file /sysApp/find. The manipulation of the argument accessKey/secretKey leads to information disclosure. It is possible to launch the…