VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 1 of 463
  • CVE-2022-0543CriKEVFeb 18, 2022
    risk 0.88cvss 10.0epss 0.99

    It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

  • CVE-2024-57726CriKEVJan 15, 2025
    risk 0.83cvss 9.9epss 0.67

    SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

  • CVE-2025-6205CriKEVAug 4, 2025
    risk 0.77cvss 9.1epss 0.71

    A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged access to the application.

  • CVE-2023-52163HigKEVFeb 3, 2025
    risk 0.77cvss 8.8epss 0.97

    Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2021-39226CriKEVOct 5, 2021
    risk 0.77cvss 9.8epss 1.00

    Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot…

  • CVE-2021-21978CriMar 3, 2021
    risk 0.75cvss 9.8epss 0.99

    VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner…

  • CVE-2020-8772CriFeb 6, 2020
    risk 0.74cvss 9.8epss 0.88

    The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

  • CVE-2019-15954CriSep 5, 2019
    risk 0.74cvss 9.9epss 0.79

    An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side.…

  • CVE-2018-6000CriJan 22, 2018
    risk 0.73cvss 9.8epss 0.85

    An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable…

  • CVE-2025-8943CriAug 14, 2025
    risk 0.72cvss 9.8epss 0.72

    The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise…

  • CVE-2021-32172CriOct 7, 2021
    risk 0.72cvss 9.8epss 0.66

    Maian Cart v3.8 contains a preauthorization remote code execution (RCE) exploit via a broken access control issue in the Elfinder plugin.

  • CVE-2017-6622CriMay 18, 2017
    risk 0.72cvss 9.8epss 0.62

    A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP…

  • CVE-2024-41730CriAug 13, 2024
    risk 0.70cvss 9.8epss 0.76

    In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality,…

  • CVE-2018-1217CriApr 9, 2018
    risk 0.70cvss 9.8epss 0.46

    Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access control check vulnerability which could potentially allow a remote unauthenticated attacker to read or…

  • CVE-2021-45467CriDec 26, 2022
    risk 0.69cvss 9.8epss 0.71

    In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi…

  • CVE-2025-46811CriJul 30, 2025
    risk 0.68cvss 9.8epss 0.10

    A Missing Authorization vulnerability in SUSE Linux Manager allows anyone with the ability to connect to port 443 of SUSE Manager is able to run any command as root on any client. This issue affects Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1: from ? before…

  • CVE-2025-5394CriJul 15, 2025
    risk 0.68cvss 9.8epss 0.49

    The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the alone_import_pack_install_plugin() function in all versions up to, and including, 7.8.3. This makes it possible for…

  • CVE-2022-1329HigApr 19, 2022
    risk 0.68cvss 8.8epss 0.93

    The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to…

  • CVE-2020-36239CriJul 29, 2021
    risk 0.68cvss 9.8epss 0.47

    Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version…

  • CVE-2026-1830CriApr 9, 2026
    risk 0.67cvss 9.8epss 0.08

    The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible…