VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,117)

page 503 of 506
  • CVE-2025-53825CriJul 14, 2025
    risk 0.00cvss 9.4epss 0.01

    Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deployment vulnerability in Dokploy allows any user to execute arbitrary code and access sensitive environment variables by simply opening a pull request on a…

  • CVE-2025-53374MedJul 7, 2025
    risk 0.00cvss 4.3epss 0.00

    Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organization by directly…

  • CVE-2025-5410MedJun 1, 2025
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability affects the function session_start_response of the file src/mist/api/auth/middleware.py. The manipulation leads to cross-site request forgery. The attack can…

  • CVE-2025-47792MedMay 16, 2025
    risk 0.00cvss 5.0epss 0.00

    Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an…

  • CVE-2025-24021MedMay 14, 2025
    risk 0.00cvss 5.0epss 0.00

    iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account having portal access can set value to object fields when they're not supposed to. Versions 2.7.12, 3.1.3, and 3.2.1 contain a fix for the issue.

  • CVE-2025-43862HigApr 25, 2025
    risk 0.00cvss 7.6epss 0.00

    Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allows non-admin users to make…

  • CVE-2025-32045MedApr 25, 2025
    risk 0.00cvss 5.3epss 0.00

    A flaw has been identified in Moodle where insufficient capability checks in certain grade reports allowed users without the necessary permissions to access hidden grades.

  • CVE-2024-7046Mar 20, 2025
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-7045Mar 20, 2025
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2024-13060MedMar 20, 2025
    risk 0.00cvss 4.3epss 0.00

    A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1.

  • CVE-2024-10363MedMar 20, 2025
    risk 0.00cvss 5.4epss 0.00

    In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowing unauthorized actions.

  • CVE-2024-50633NonJan 16, 2025
    risk 0.00cvss 0.0epss 0.01

    A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the Supplier because the product intentionally lets all users…

  • CVE-2024-53473HigDec 7, 2024
    risk 0.00cvss 7.5epss 0.01

    WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

  • CVE-2024-54679MedDec 5, 2024
    risk 0.00cvss 4.3epss 0.01

    CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

  • CVE-2024-53258MedNov 25, 2024
    risk 0.00cvss 5.3epss 0.00

    Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for…

  • CVE-2024-52554HigNov 13, 2024
    risk 0.00cvss 8.8epss 0.01

    Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a…

  • CVE-2024-52549MedNov 13, 2024
    risk 0.00cvss 4.3epss 0.00

    Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the…

  • CVE-2024-47768HigOct 4, 2024
    risk 0.00cvss 8.1epss 0.01

    Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct…

  • CVE-2024-9202MedSep 27, 2024
    risk 0.00cvss 5.3epss 0.00

    In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, to ensure that only authorized parties are able to view restricted offers. However, there is the possibility to…

  • CVE-2024-45393MedSep 10, 2024
    risk 0.00cvss 6.4epss 0.00

    Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account can access webhook delivery information for any webhook registered on the CVAT instance, including that of other users. For each…