VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,083)

page 33 of 405
  • CVE-2024-11045CriMar 20, 2025
    risk 0.62cvss 9.6epss 0.00

    A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections…

  • CVE-2025-21293HigJan 14, 2025
    risk 0.62cvss 8.8epss 0.19

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2023-29121CriNov 5, 2024
    risk 0.62cvss 9.6epss 0.00

    Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

  • CVE-2024-38175CriAug 20, 2024
    risk 0.62cvss 9.6epss 0.01

    An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network.

  • CVE-2024-38164CriJul 23, 2024
    risk 0.62cvss 9.6epss 0.01

    An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link.

  • CVE-2023-46601CriNov 14, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that the user should not have access to.

  • CVE-2023-43505CriNov 14, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.

  • CVE-2023-21742HigJan 10, 2023
    risk 0.62cvss 8.8epss 0.56

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2023-0017CriJan 10, 2023
    risk 0.62cvss 9.4epss 0.16

    An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and…

  • CVE-2026-81046CriSep 10, 2026
    risk 0.61cvss 9.4epss 0.01

    Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.

  • CVE-2026-76312CriAug 19, 2026
    risk 0.61cvss 9.4epss 0.00

    In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system…

  • CVE-2026-76311CriAug 19, 2026
    risk 0.61cvss 9.4epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system…

  • CVE-2026-76310CriAug 19, 2026
    risk 0.61cvss 9.4epss 0.00

    In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report…

  • CVE-2026-73920CriAug 18, 2026
    risk 0.61cvss 9.4epss 0.00

    Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. …

  • CVE-2026-71167CriAug 18, 2026
    risk 0.61cvss 9.4epss 0.00

    Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. …

  • CVE-2026-71166CriAug 18, 2026
    risk 0.61cvss 9.4epss 0.00

    Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. …

  • CVE-2026-62629CriAug 18, 2026
    risk 0.61cvss 9.4epss 0.00

    Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authentication). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-61203CriJul 21, 2026
    risk 0.61cvss 9.4epss 0.00

    Vulnerability in the PeopleSoft Enterprise FIN Expenses product of Oracle PeopleSoft (component: Expenses). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft…

  • CVE-2024-39943CriJul 4, 2024
    risk 0.61cvss 9.9epss 0.39

    rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process…

  • CVE-2024-21767CriMar 1, 2024
    risk 0.61cvss 9.4epss 0.01

    A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.