VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 46 of 405
  • CVE-2015-1000009CriOct 6, 2016
    risk 0.59cvss 9.1epss 0.02

    Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05

  • CVE-2016-4694CriSep 25, 2016
    risk 0.59cvss 9.1epss 0.01

    The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to…

  • CVE-2016-4501CriMay 31, 2016
    risk 0.59cvss 9.1epss 0.02

    Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier mishandles sessions, which allows remote attackers to bypass authentication and make arbitrary configuration changes via unspecified vectors.

  • CVE-2016-0188HigMay 11, 2016
    risk 0.59cvss 8.8epss 0.18

    The User Mode Code Integrity (UMCI) implementation in Device Guard in Microsoft Internet Explorer 11 allows remote attackers to bypass a code-signing protection mechanism via unspecified vectors, aka "Internet Explorer Security Feature Bypass."

  • CVE-2015-8361CriFeb 8, 2016
    risk 0.59cvss 9.1epss 0.03

    Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port.

  • CVE-2026-83304HigSep 15, 2026
    risk 0.58cvss 8.9epss 0.00

    Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows unauthenticated…

  • CVE-2026-54745CriAug 28, 2026
    risk 0.58cvss 10.0epss 0.00

    Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in…

  • CVE-2026-46695CriJun 10, 2026
    risk 0.58cvss 10.0epss 0.00

    Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can…

  • CVE-2026-5786HigMay 7, 2026
    risk 0.58cvss 8.8epss 0.12

    An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

  • CVE-2026-33309CriMar 24, 2026
    risk 0.58cvss 9.9epss 0.11

    Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through 1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root architectural issue within `LocalStorageService` remaining unresolved.…

  • CVE-2026-32737CriMar 18, 2026
    risk 0.58cvss 10.0epss 0.00

    Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.1, due to a mis-written NetworkPolicy, a malicious actor can pivot from the "hardened"…

  • CVE-2026-30966CriMar 10, 2026
    risk 0.58cvss 10.0epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field mappings such as role memberships, can be directly accessed via the REST API or…

  • CVE-2024-1675HigFeb 21, 2024
    risk 0.58cvss 8.8epss 0.11

    Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-31259CriMay 21, 2022
    risk 0.58cvss 9.8epss 0.22

    The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).

  • CVE-2021-35213HigAug 31, 2021
    risk 0.58cvss 8.9epss 0.03

    An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a guest user to elevate privileges to the Administrator using this vulnerability. Authentication is required to exploit the…

  • CVE-2018-15640HigApr 9, 2019
    risk 0.58cvss 8.8epss 0.08

    Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.

  • CVE-2018-8088CriMar 20, 2018
    risk 0.58cvss 9.8epss 0.15

    org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x…

  • CVE-2015-2692CriJun 8, 2017
    risk 0.58cvss 10.0epss 0.02

    AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters.

  • CVE-2016-7408HigMar 3, 2017
    risk 0.58cvss 8.8epss 0.04

    The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.

  • CVE-2016-4286HigOct 13, 2016
    risk 0.58cvss 8.8epss 0.06

    Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.