VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,268)

page 83 of 464
  • CVE-2025-41339HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_sociedad' in '/backend/api/buscarTipoDenuncia.php'.

  • CVE-2025-41338HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarTestigoByIdDenunciaUsuario.php'.

  • CVE-2025-41337HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarSSOParametros.php'.

  • CVE-2025-41336HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros.php'.

  • CVE-2025-41335HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id' and ' 'id_sociedad' in '/api/buscarEmpresaById.php'.

  • CVE-2025-41114HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameters 'id_denuncia' and 'id_user' in '/backend/api/buscarDocumentosByIdDenunciaUsuario.php'.

  • CVE-2025-41113HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarDenunciaByPin.php'.

  • CVE-2025-41112HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'web' in '/backend/api/buscarConfiguracionParametros2.php'.

  • CVE-2025-41111HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to access other users' information by sending a POST through the parameter 'id_denuncia' in '/backend/api/buscarComentariosByDenuncia.php'.

  • CVE-2025-11890HigNov 4, 2025
    risk 0.49cvss 7.5epss 0.00

    The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a payments status through server-side validation though the…

  • CVE-2025-9954HigOct 30, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Drupal Acquia DAM allows Forceful Browsing.This issue affects Acquia DAM: from 0.0.0 before 1.1.5.

  • CVE-2025-59461HigOct 27, 2025
    risk 0.49cvss 7.6epss 0.00

    A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

  • CVE-2025-62022HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in BuddyPress BuddyPress buddypress.This issue affects BuddyPress: from n/a through <= 14.3.4.

  • CVE-2025-49925HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.7.

  • CVE-2025-30944HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Tablesome Table Premium: from n/a through <= 1.1.23.

  • CVE-2025-33182HigOct 14, 2025
    risk 0.49cvss 7.6epss 0.00

    NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause corruption of the Linux Device Tree. A successful exploitation of this vulnerability might lead to data tampering, denial of service.

  • CVE-2025-59011HigSep 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through < 3.2.3.

  • CVE-2025-59826HigSep 23, 2025
    risk 0.49cvss 7.6epss 0.00

    Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, potentially introducing malicious, incorrect, or misleading content. This issue has been patched in version 2.2.0.

  • CVE-2025-59353HigSep 17, 2025
    risk 0.49cvss 7.5epss 0.00

    Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer can obtain a valid TLS certificate for arbitrary IP addresses, effectively rendering the mTLS authentication useless. The issue is that the Manager’s Certificate gRPC…

  • CVE-2025-55148HigSep 9, 2025
    risk 0.49cvss 7.6epss 0.01

    Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with…