VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 338 of 404
  • CVE-2025-11641LowOct 12, 2025
    risk 0.25cvss 3.9epss 0.00

    A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This manipulation causes improper access controls. It is feasible to perform the attack on the physical device. The attack is…

  • CVE-2025-44657LowJul 21, 2025
    risk 0.25cvss 3.9epss 0.00

    In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

  • CVE-2024-21247LowOct 15, 2024
    risk 0.25cvss 3.8epss 0.01

    Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via…

  • CVE-2024-5470LowJul 11, 2024
    risk 0.25cvss 3.8epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with `admin_push_rules` permission may have been able to create project-level deploy tokens.

  • CVE-2024-3270LowApr 3, 2024
    risk 0.25cvss 3.8epss 0.01

    A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to…

  • CVE-2023-27303LowFeb 14, 2024
    risk 0.25cvss 3.8epss 0.00

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2024-22407MedJan 16, 2024
    risk 0.25cvss 4.9epss 0.00

    Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently verify user authorizations for actions that modify the payment, delivery, and/or order status. Due to this inadequate implementation, users lacking 'write'…

  • CVE-2023-38411LowNov 14, 2023
    risk 0.25cvss 3.9epss 0.00

    Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-0091LowJan 13, 2023
    risk 0.25cvss 3.8epss 0.00

    A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.

  • CVE-2022-39910LowDec 8, 2022
    risk 0.25cvss 3.9epss 0.00

    Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view.

  • CVE-2022-36851LowSep 9, 2022
    risk 0.25cvss 3.9epss 0.00

    Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.

  • CVE-2022-1553MedMay 16, 2022
    risk 0.25cvss 4.9epss 0.01

    Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the publify website, compromising…

  • CVE-2019-14838MedOct 14, 2019
    risk 0.25cvss 4.9epss 0.01

    A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server

  • CVE-2017-18384LowAug 2, 2019
    risk 0.25cvss 3.8epss 0.00

    cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).

  • CVE-2016-3159LowApr 13, 2016
    risk 0.25cvss 3.8epss 0.00

    The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending…

  • CVE-2016-3158LowApr 13, 2016
    risk 0.25cvss 3.8epss 0.00

    The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception…

  • CVE-2026-92247MedSep 16, 2026
    risk 0.24cvss 4.7epss 0.00

    A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The…

  • CVE-2026-13144LowSep 9, 2026
    risk 0.24cvss 3.7epss 0.00

    The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of its bank-deposit handler, allowing an unauthenticated attacker who knows the target customer's email address to reset that…

  • CVE-2026-66788LowAug 20, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to…

  • CVE-2026-73923LowAug 18, 2026
    risk 0.24cvss 3.7epss 0.00

    Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. …