VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,735)

page 11 of 187
  • CVE-2025-29757CriJul 19, 2025
    risk 0.61cvss epss 0.00

    An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account to transfer any plant into his/her account.

  • CVE-2025-48757CriMay 30, 2025
    risk 0.61cvss 9.3epss 0.01

    An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual customer of the Lovable…

  • CVE-2025-3476CriMay 7, 2025
    risk 0.61cvss epss 0.00

    Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4.

  • CVE-2024-21287HigKEVNov 18, 2024
    risk 0.61cvss 7.5epss 0.01

    Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2023-32749HigJun 8, 2023
    risk 0.61cvss 8.8epss 0.14

    Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it is possible to assign the new user arbitrary roles. By assigning all roles to a newly created…

  • CVE-2018-15767HigNov 30, 2018
    risk 0.61cvss 8.8epss 0.12

    The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file.

  • CVE-2026-13738CriAug 11, 2026
    risk 0.60cvss epss 0.01

    CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents,…

  • CVE-2026-13737CriAug 11, 2026
    risk 0.60cvss epss 0.00

    CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale…

  • CVE-2026-48321CriJul 14, 2026
    risk 0.60cvss 9.3epss 0.00

    ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by…

  • CVE-2026-34660CriMay 12, 2026
    risk 0.60cvss 9.3epss 0.00

    Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web…

  • CVE-2024-5539CriNov 27, 2025
    risk 0.60cvss epss 0.00

    The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.

  • CVE-2025-26850CriJul 5, 2025
    risk 0.60cvss 9.3epss 0.00

    The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.

  • CVE-2025-53391CriJun 28, 2025
    risk 0.60cvss 9.3epss 0.00

    The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through the zulucrypt_6.2.0-1 package has insecure PolicyKit allow_any/allow_inactive/allow_active settings that allow a local user to escalate their privileges to root.

  • CVE-2025-43564CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.15

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper…

  • CVE-2025-43561CriMay 13, 2025
    risk 0.60cvss 9.1epss 0.21

    ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass…

  • CVE-2025-24434CriFeb 11, 2025
    risk 0.60cvss 9.1epss 0.17

    Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain…

  • CVE-2024-48548CriOct 24, 2024
    risk 0.60cvss 9.3epss 0.00

    The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows attackers to arbitrarily construct a request to use the app to bind to unknown devices by finding a valid serial number via a bruteforce attack.

  • CVE-2023-21715HigKEVFeb 14, 2023
    risk 0.60cvss 7.3epss 0.12

    Microsoft Publisher Security Feature Bypass Vulnerability

  • CVE-2022-0143CriSep 19, 2022
    risk 0.60cvss 9.3epss 0.01

    When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)

  • CVE-2021-3560HigKEVFeb 16, 2022
    risk 0.60cvss 7.8epss 0.22

    It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest…