VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,733)

page 1 of 187
  • CVE-2023-22518CriKEVOct 31, 2023
    risk 0.93cvss 9.8epss 1.00

    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an…

  • CVE-2023-38035CriKEVAug 21, 2023
    risk 0.93cvss 9.8epss 1.00

    A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

  • CVE-2019-7192CriKEVDec 5, 2019
    risk 0.92cvss 9.8epss 0.88

    This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

  • CVE-2018-13382CriKEVJun 4, 2019
    risk 0.87cvss 9.1epss 0.82

    An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN…

  • CVE-2025-54253CriKEVAug 5, 2025
    risk 0.84cvss 10.0epss 0.88

    Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration vulnerability that could result in arbitrary code execution. An attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not…

  • CVE-2024-38856CriKEVAug 5, 2024
    risk 0.80cvss 9.8epss 0.99

    Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some…

  • CVE-2024-45216CriOct 16, 2024
    risk 0.71cvss 9.8epss 0.91

    Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests…

  • CVE-2025-21479HigKEVJun 3, 2025
    risk 0.68cvss 8.6epss 0.01

    Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

  • CVE-2025-21480HigKEVJun 3, 2025
    risk 0.68cvss 8.6epss 0.00

    Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

  • CVE-2021-45466CriDec 26, 2022
    risk 0.68cvss 9.8epss 0.55

    In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.

  • CVE-2021-40655HigKEVSep 24, 2021
    risk 0.68cvss 7.5epss 0.87

    An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

  • CVE-2010-2965CriAug 5, 2010
    risk 0.68cvss 9.8epss 0.58

    The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls,…

  • CVE-2023-34051CriOct 20, 2023
    risk 0.67cvss 9.8epss 0.45

    VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

  • CVE-2023-26258CriJul 3, 2023
    risk 0.67cvss 9.8epss 0.38

    Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be…

  • CVE-2024-6782CriAug 6, 2024
    risk 0.66cvss 9.8epss 0.84

    Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.

  • CVE-2023-20048CriNov 1, 2023
    risk 0.66cvss 9.9epss 0.16

    A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software.…

  • CVE-2022-32532CriJun 29, 2022
    risk 0.66cvss 9.8epss 0.26

    Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

  • CVE-2018-13324CriNov 26, 2018
    risk 0.66cvss 9.8epss 0.23

    Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header.

  • CVE-2026-71398CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not…

  • CVE-2026-27302CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not…