VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 341 of 404
  • CVE-2026-7021LowApr 26, 2026
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in SmythOS sre up to 0.0.15. This impacts an unknown function of the file packages/sdk/src/LLM/utils.ts of the component Connector Service. This manipulation of the argument baseURL causes information disclosure. It is possible to initiate the…

  • CVE-2026-24509LowMar 11, 2026
    risk 0.23cvss 3.6epss 0.00

    Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2025-64746MedNov 13, 2025
    risk 0.23cvss 4.6epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does not properly clean up field-level permissions when a field is deleted. When a field is removed from a collection, its reference in the permissions table…

  • CVE-2025-55795LowSep 29, 2025
    risk 0.23cvss 3.5epss 0.00

    The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with a lower user ID can update their email address to that of…

  • CVE-2025-11026LowSep 26, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in givanz Vvveb up to 1.0.7.2. Affected by this vulnerability is an unknown functionality of the component Configuration File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-27238LowSep 12, 2025
    risk 0.23cvss 3.5epss 0.00

    Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.

  • CVE-2025-30731LowApr 15, 2025
    risk 0.23cvss 3.6epss 0.00

    Vulnerability in the Oracle Applications Technology Stack product of Oracle E-Business Suite (component: Configuration). Supported versions that are affected are 12.2.3-12.2.14. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure…

  • CVE-2025-30700LowApr 15, 2025
    risk 0.23cvss 3.5epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris. …

  • CVE-2025-24429LowFeb 11, 2025
    risk 0.23cvss 3.5epss 0.01

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged attacker could leverage this…

  • CVE-2024-36261LowSep 16, 2024
    risk 0.23cvss 3.5epss 0.00

    Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.

  • CVE-2024-38518MedJun 28, 2024
    risk 0.23cvss 4.6epss 0.00

    BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a valid join link to a meeting can trick BigBlueButton into generating a signed join link with additional parameters. One of those parameters may be…

  • CVE-2024-30107LowApr 18, 2024
    risk 0.23cvss 3.5epss 0.00

    HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized users in certain scenarios.

  • CVE-2023-40170MedAug 28, 2023
    risk 0.23cvss 4.6epss 0.01

    jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". This issue has been addressed in…

  • CVE-2023-4546LowAug 26, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /sysmanage/licence.php. The manipulation leads to improper access controls. The exploit…

  • CVE-2023-33191MedMay 30, 2023
    risk 0.23cvss 4.6epss 0.00

    Kyverno is a policy engine designed for Kubernetes. Kyverno seccomp control can be circumvented. Users of the podSecurity `validate.podSecurity` subrule in Kyverno 1.9.2 and 1.9.3 are vulnerable. This issue was patched in version 1.9.4.

  • CVE-2023-2112LowApr 20, 2023
    risk 0.23cvss 3.6epss 0.00

    Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.

  • CVE-2015-10057MedJan 16, 2023
    risk 0.23cvss 4.6epss 0.01

    A vulnerability was found in Little Apps Little Software Stats. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file inc/class.securelogin.php of the component Password Reset Handler. The manipulation leads to improper access…

  • CVE-2022-34894LowJul 1, 2022
    risk 0.23cvss 3.5epss 0.01

    In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services

  • CVE-2020-8902LowFeb 23, 2021
    risk 0.23cvss 3.5epss 0.00

    Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot.…

  • CVE-2016-4874LowApr 17, 2017
    risk 0.23cvss 3.5epss 0.01

    Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.