VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,080)

page 359 of 404
  • CVE-2015-3148Apr 24, 2015
    risk 0.01cvss —epss 0.14

    cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.

  • CVE-2015-1631Mar 11, 2015
    risk 0.01cvss —epss 0.09

    Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vectors, aka "Exchange Forged Meeting Request Spoofing Vulnerability."

  • CVE-2015-0227Feb 12, 2015
    risk 0.01cvss —epss 0.08

    Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors related to "wrapping attacks."

  • CVE-2014-8680Dec 11, 2014
    risk 0.01cvss —epss 0.09

    The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.

  • CVE-2014-6319Dec 11, 2014
    risk 0.01cvss —epss 0.10

    Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified vectors, aka "Outlook Web App Token…

  • CVE-2013-0155Jan 13, 2013
    risk 0.01cvss —epss 0.08

    Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query…

  • CVE-2012-5885Nov 17, 2012
    risk 0.01cvss —epss 0.09

    The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count)…

  • CVE-2026-72585Aug 10, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.

  • CVE-2026-15430MedAug 3, 2026
    risk 0.00cvss 6.2epss 0.00

    Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and…

  • CVE-2026-66803CriJul 30, 2026
    risk 0.00cvss 10.0epss 0.01

    Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

  • CVE-2026-15250MedJul 30, 2026
    risk 0.00cvss 5.3epss 0.00

    The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and…

  • CVE-2026-11782MedJul 30, 2026
    risk 0.00cvss 5.9epss 0.00

    The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing…

  • CVE-2026-63236LowJul 29, 2026
    risk 0.00cvss 3.7epss 0.00

    An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and cached lesson state via the SCORM API endpoint.

  • CVE-2026-63235LowJul 29, 2026
    risk 0.00cvss 3.7epss 0.00

    An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service.

  • CVE-2026-7362MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an authenticated user to obtain sensitive information that should only be available to a…

  • CVE-2026-62427HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations are used by the control domain or a possible Xenstore domain. Some of these operations may not…

  • CVE-2026-18038MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. Executing a manipulation can lead to information disclosure. The attack…

  • CVE-2026-14926MedJul 28, 2026
    risk 0.00cvss 4.2epss 0.00

    The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's subscription (changing its…

  • CVE-2021-32084CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be…

  • CVE-2026-64737HigJul 27, 2026
    risk 0.00cvss 8.2epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.