VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 61 of 405
  • CVE-2025-20341HigNov 13, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this…

  • CVE-2025-54968HigOct 27, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some configurations, this may allow remote users to submit jobs, or local users to submit jobs that will execute with the permissions of other users.

  • CVE-2025-52079HigOct 21, 2025
    risk 0.57cvss 8.8epss 0.01

    The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.

  • CVE-2025-62159HigOct 10, 2025
    risk 0.57cvss —epss 0.00

    External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider implementation for External Secrets Operator versions 0.10.1 through 0.19.2. The provider…

  • CVE-2025-60305HigOct 10, 2025
    risk 0.57cvss 8.8epss 0.00

    SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a logic flaw which allows low privilege users can forge high privileged sessions and perform sensitive operations.

  • CVE-2025-10957HigSep 25, 2025
    risk 0.57cvss —epss 0.00

    This vulnerability exists in the Syrotech SY-GPON-2010-WADONT router due to improper access control in its FTP service. A remote attacker could exploit this vulnerability by establishing an FTP connection using default credentials, potentially gaining unauthorized access to…

  • CVE-2025-10201HigSep 10, 2025
    risk 0.57cvss 8.8epss 0.00

    Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-55368HigAug 21, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

  • CVE-2025-24999HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.02

    Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-43270HigJul 30, 2025
    risk 0.57cvss 8.8epss 0.00

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may gain unauthorized access to Local Network.

  • CVE-2024-42655HigJul 29, 2025
    risk 0.57cvss 8.8epss 0.00

    An access control issue in NanoMQ v0.21.10 allows attackers to bypass security restrictions and access sensitive system topic messages using MQTT wildcard characters.

  • CVE-2025-48817HigJul 8, 2025
    risk 0.57cvss 8.8epss 0.01

    Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2025-53501HigJul 3, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper Access Control vulnerability in Wikimedia Foundation Mediawiki - Scribunto Extension allows : Accessing Functionality Not Properly Constrained by Authorization.This issue affects Mediawiki - Scribunto Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7,…

  • CVE-2025-45081HigJul 1, 2025
    risk 0.57cvss 8.8epss 0.00

    Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.

  • CVE-2025-46014HigJun 30, 2025
    risk 0.57cvss 8.8epss 0.00

    Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation.

  • CVE-2025-49154HigJun 17, 2025
    risk 0.57cvss 8.7epss 0.00

    An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. …

  • CVE-2024-57190CriJun 10, 2025
    risk 0.57cvss 9.8epss 0.01

    Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.

  • CVE-2025-4433HigMay 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Management" and "User Group Management" permissions to perform privilege escalation by adding users to groups with administrative…

  • CVE-2025-22157HigMay 20, 2025
    risk 0.57cvss 8.8epss 0.01

    This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege…

  • CVE-2025-46331CriApr 30, 2025
    risk 0.57cvss 9.8epss 0.00

    OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject…