VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 351 of 404
  • CVE-2023-4105LowAug 11, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able to access and download the attachment of a deleted message

  • CVE-2023-0858LowMay 11, 2023
    risk 0.20cvss 3.1epss 0.01

    Improper Authentication of RemoteUI of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger unauthorized access to the product. *:Satera LBP660C Series/LBP620C Series/MF740C Series/MF640C Series firmware…

  • CVE-2023-28443MedMar 24, 2023
    risk 0.20cvss 4.2epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This issue is patched in version…

  • CVE-2020-3126LowApr 13, 2020
    risk 0.20cvss 3.0epss 0.01

    vulnerability within the Multimedia Viewer feature of Cisco Webex Meetings could allow an authenticated, remote attacker to bypass security protections. The vulnerability is due to missing security warning dialog boxes when a room host views shared multimedia files. An…

  • CVE-2019-1866LowApr 13, 2020
    risk 0.20cvss 3.1epss 0.00

    Cisco Webex Business Suite before 39.1.0 contains a vulnerability that could allow an unauthenticated, remote attacker to affect the integrity of the application. The vulnerability is due to improper validation of host header values. An attacker with a privileged network…

  • CVE-2017-18404LowAug 2, 2019
    risk 0.20cvss 3.1epss 0.00

    cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).

  • CVE-2016-8942LowFeb 1, 2017
    risk 0.20cvss 3.1epss 0.00

    IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.

  • CVE-2016-2874LowNov 30, 2016
    risk 0.20cvss 3.1epss 0.01

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

  • CVE-2016-8288LowOct 25, 2016
    risk 0.20cvss 3.1epss 0.02

    Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect integrity via vectors related to Server: InnoDB Plugin.

  • CVE-2016-5506LowOct 25, 2016
    risk 0.20cvss 3.1epss 0.00

    Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware allows local users to affect confidentiality and integrity via vectors related to App Server.

  • CVE-2015-7490LowMar 3, 2016
    risk 0.20cvss 3.1epss 0.01

    IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.

  • CVE-2026-61096LowJul 21, 2026
    risk 0.19cvss 2.9epss 0.00

    Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit…

  • CVE-2025-65852medFeb 6, 2026
    risk 0.19cvss —epss 0.00

    ### Summary The DELETE /api/v1/repos/:owner/:repo endpoint lacks necessary permission validation middleware. Consequently, any user with read access (including read-only collaborators) can delete the entire repository. This vulnerability stems from the API route configuration…

  • CVE-2025-64715MedNov 29, 2025
    risk 0.19cvss 4.0epss 0.00

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.17.10, and 1.18.4, CiliumNetworkPolicys which use egress.toGroups.aws.securityGroupsIds to reference AWS security group IDs that do not exist or are not…

  • CVE-2015-8801LowJun 30, 2016
    risk 0.19cvss 2.9epss 0.00

    Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device.

  • CVE-2026-82126LowSep 16, 2026
    risk 0.18cvss 2.7epss 0.00

    The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the content of other users' draft, pending,…

  • CVE-2026-19835LowAug 14, 2026
    risk 0.18cvss 3.8epss 0.00

    A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is…

  • CVE-2026-55984LowAug 13, 2026
    risk 0.18cvss 2.7epss 0.00

    Null Pointer Dereference in AddTime API Causes Authenticated Denial of Service

  • CVE-2026-70430LowAug 5, 2026
    risk 0.18cvss 2.7epss 0.00

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration,…

  • CVE-2025-14083LowJan 21, 2026
    risk 0.18cvss 2.7epss 0.00

    A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targeted attacks or privilege escalation via improper access control.