VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 62 of 405
  • CVE-2025-1568HigApr 16, 2025
    risk 0.57cvss 8.8epss 0.00

    Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via…

  • CVE-2025-28409HigApr 7, 2025
    risk 0.57cvss 8.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId

  • CVE-2025-28407HigApr 7, 2025
    risk 0.57cvss 8.8epss 0.01

    An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId

  • CVE-2025-25598HigMar 13, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a crafted executable into a scheduled task.

  • CVE-2025-26645HigMar 11, 2025
    risk 0.57cvss 8.8epss 0.03

    Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

  • CVE-2025-25614HigMar 10, 2025
    risk 0.57cvss 8.8epss 0.01

    Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of fellow teachers.

  • CVE-2024-38291HigFeb 27, 2025
    risk 0.57cvss 8.8epss 0.00

    In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege escalation.

  • CVE-2024-37355HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-46432HigFeb 10, 2025
    risk 0.57cvss 8.8epss 0.01

    Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized changes to WiFi configuration settings and administrative credentials.

  • CVE-2025-24968HigFeb 4, 2025
    risk 0.57cvss 8.8epss 0.01

    reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tester` or `auditor` to delete all projects in the system. This can lead to a complete system takeover…

  • CVE-2024-23920HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists within the onboardee module. The issue…

  • CVE-2025-21380HigJan 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.

  • CVE-2024-47760HigDec 11, 2024
    risk 0.57cvss 8.8epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to the API can take control of an account with higher privileges. Version 10.0.17 contains a patch for this issue.

  • CVE-2024-47758HigDec 11, 2024
    risk 0.57cvss 8.8epss 0.00

    GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.

  • CVE-2024-8805HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.02

    BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2024-51734HigNov 4, 2024
    risk 0.57cvss —epss 0.00

    Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2.…

  • CVE-2024-46280HigSep 30, 2024
    risk 0.57cvss 8.8epss 0.00

    PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a root-level account, without the possibility of changing them.

  • CVE-2024-45982HigSep 26, 2024
    risk 0.57cvss 8.8epss 0.00

    A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.

  • CVE-2024-8779HigSep 16, 2024
    risk 0.57cvss 8.8epss 0.01

    OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regular privileges to update system settings or create accounts with administrator privileges, thereby gaining control of the server.

  • CVE-2024-44571HigSep 11, 2024
    risk 0.57cvss 8.8epss 0.00

    RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.