VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,257)

page 108 of 213
  • CVE-2023-25594MedMar 22, 2023
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of this vulnerability allows an attacker…

  • CVE-2022-1499MedJul 26, 2022
    risk 0.41cvss 6.3epss 0.01

    Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

  • CVE-2021-35526MedSep 8, 2021
    risk 0.41cvss 6.3epss 0.00

    Backup file without encryption vulnerability is found in Hitachi ABB Power Grids System Data Manager – SDM600 allows attacker to gain access to sensitive information. This issue affects: Hitachi ABB Power Grids System Data Manager – SDM600 1.2 versions prior to FP2 HF6…

  • CVE-2021-24282MedMay 14, 2021
    risk 0.41cvss 6.3epss 0.01

    In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the various AJAX actions in the plugin to do a variety of things. For example, an attacker could use wpcf7r_reset_settings to reset the plugin’s…

  • CVE-2020-27901MedApr 2, 2021
    risk 0.41cvss 6.3epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2021-1270MedJan 20, 2021
    risk 0.41cvss 6.3epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the…

  • CVE-2021-1269MedJan 20, 2021
    risk 0.41cvss 6.3epss 0.01

    Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the…

  • CVE-2020-3522MedAug 26, 2020
    risk 0.41cvss 6.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to bypass authorization on an affected device and access sensitive information that is related to the device. The…

  • CVE-2020-16241MedAug 21, 2020
    risk 0.41cvss 6.3epss 0.00

    Philips SureSigns VS4, A.07.107 and prior does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CVE-2020-14486MedJul 29, 2020
    risk 0.41cvss 6.3epss 0.01

    An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands.

  • CVE-2020-7692HigJul 9, 2020
    risk 0.41cvss 7.4epss 0.02

    PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarantee that the client that issued the initial authorization request is the one that…

  • CVE-2020-13277MedJun 19, 2020
    risk 0.41cvss 6.3epss 0.02

    An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

  • CVE-2020-12875MedMay 14, 2020
    risk 0.41cvss 6.3epss 0.01

    Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain unauthorized access to sensitive information or functionality by manipulating specific parameters within the application.

  • CVE-2019-19984MedDec 26, 2019
    risk 0.41cvss 6.3epss 0.01

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.

  • CVE-2018-14665MedOct 25, 2018
    risk 0.41cvss 6.6epss 0.27

    A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run…

  • CVE-2018-1000152MedApr 5, 2018
    risk 0.41cvss 6.3epss 0.01

    An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSphereCloudProperty.java,…

  • CVE-2016-9575MedMar 13, 2018
    risk 0.41cvss 6.3epss 0.01

    Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates…

  • CVE-2017-6590MedMar 9, 2017
    risk 0.41cvss 6.3epss 0.00

    An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login screen to access local files and execute arbitrary commands as the lightdm user.…

  • CVE-2026-100744HigSep 27, 2026
    risk 0.40cvss 7.3epss 0.00

    A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be…

  • CVE-2026-100530HigSep 26, 2026
    risk 0.40cvss 7.3epss 0.00

    OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to execute in different directories. Attackers with an allow-always approval can reuse it to run the same command against unreviewed files or…