VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (8,082)

page 77 of 405
  • CVE-2026-21997HigApr 21, 2026
    risk 0.55cvss 8.5epss 0.00

    Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common Core). Supported versions that are affected are 9.2.1-9.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2025-48619HigMar 2, 2026
    risk 0.55cvss 8.4epss 0.00

    In multiple functions of ContentProvider.java, there is a possible way for an app with read-only access to truncate files due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2025-14338HigJan 14, 2026
    risk 0.55cvss —epss 0.00

    Polkit authentication dis isabled by default and a race condition in the Polkit authorization check in versions before v0.69.0 can lead to the same issues as in CVE-2025-66005.

  • CVE-2025-68716HigJan 8, 2026
    risk 0.55cvss 8.4epss 0.00

    KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The root account is configured with no password, and administrators cannot disable SSH or enforce authentication via the CLI or web GUI. This allows any LAN-adjacent…

  • CVE-2025-66223HigNov 29, 2025
    risk 0.55cvss —epss 0.00

    OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different…

  • CVE-2025-53049HigOct 21, 2025
    risk 0.55cvss 8.4epss 0.00

    Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with…

  • CVE-2025-10847HigOct 1, 2025
    risk 0.55cvss —epss 0.00

    DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.

  • CVE-2025-32992HigAug 18, 2025
    risk 0.55cvss 8.5epss 0.00

    Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.

  • CVE-2025-26678HigApr 8, 2025
    risk 0.55cvss 8.4epss 0.01

    Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2024-51954HigMar 3, 2025
    risk 0.55cvss 8.5epss 0.00

    There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under unique circumstances, could allow a remote, low‑privileged authenticated attacker to access secure services published to a standalone (unfederated) ArcGIS…

  • CVE-2024-49105HigDec 12, 2024
    risk 0.55cvss 8.4epss 0.02

    Remote Desktop Client Remote Code Execution Vulnerability

  • CVE-2016-10408HigNov 26, 2024
    risk 0.55cvss 8.4epss 0.00

    QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.

  • CVE-2024-41605HigSep 26, 2024
    risk 0.55cvss 8.4epss 0.00

    In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be…

  • CVE-2024-43479HigSep 10, 2024
    risk 0.55cvss 8.5epss 0.01

    Microsoft Power Automate Desktop Remote Code Execution Vulnerability

  • CVE-2024-33027HigAug 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.

  • CVE-2024-5650HigJun 17, 2024
    risk 0.55cvss 8.5epss 0.00

    DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into a computer that installed affected product or access to a shared folder, by replacing the DLL file with a tampered one,…

  • CVE-2024-23360HigJun 3, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.

  • CVE-2024-23351HigMay 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

  • CVE-2024-33396HigMay 2, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

  • CVE-2023-38297HigApr 22, 2024
    risk 0.55cvss 8.4epss 0.01

    An issue was discovered in a third-party com.factory.mmigroup component, shipped on devices from multiple device manufacturers. Certain software builds for various Android devices contain a vulnerable pre-installed app with a package name of com.factory.mmigroup…