VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 11 of 209
  • CVE-2001-1155CriAug 23, 2001
    risk 0.64cvss 9.8epss 0.02

    TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.

  • CVE-2025-29927CriMar 21, 2025
    risk 0.63cvss 9.1epss 0.99

    Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in…

  • CVE-2021-32829CriAug 17, 2021
    risk 0.63cvss 9.6epss 0.03

    ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networking all by APIs. Affected versions of ZStack REST API are vulnerable to post-authentication Remote Code Execution (RCE) via bypass…

  • CVE-2020-13957CriOct 13, 2020
    risk 0.63cvss 9.8epss 0.79

    Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to…

  • CVE-2017-3891CriNov 14, 2017
    risk 0.63cvss 9.6epss 0.01

    In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with QNet enabled on networks comprising two or more QNet nodes could allow an attacker to access local and remote files or take…

  • CVE-2026-90942CriSep 14, 2026
    risk 0.62cvss 9.6epss 0.00

    Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any…

  • CVE-2026-87492CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.00

    Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84354CriSep 2, 2026
    risk 0.62cvss 9.6epss 0.00

    Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-53552CriAug 31, 2026
    risk 0.62cvss 9.6epss 0.00

    Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without…

  • CVE-2026-56443CriAug 13, 2026
    risk 0.62cvss 9.6epss 0.00

    Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

  • CVE-2026-71384CriAug 11, 2026
    risk 0.62cvss 9.6epss 0.00

    is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application…

  • CVE-2026-25293CriMay 4, 2026
    risk 0.62cvss 9.6epss 0.00

    Buffer overflow due to incorrect authorization in PLC FW

  • CVE-2024-23629CriJan 26, 2024
    risk 0.62cvss 9.6epss 0.01

    An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.

  • CVE-2023-31403CriNov 14, 2023
    risk 0.62cvss 9.6epss 0.00

    SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by…

  • CVE-2023-30429CriJul 12, 2023
    risk 0.62cvss 9.6epss 0.01

    Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. When a client connects to the Pulsar Function Worker via the Pulsar Proxy where the Pulsar Proxy uses mTLS authentication to…

  • CVE-2023-0971CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

  • CVE-2023-35166CriJun 20, 2023
    risk 0.62cvss 9.9epss 0.62

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5.

  • CVE-2022-1309CriJul 25, 2022
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-3577HigNov 12, 2021
    risk 0.62cvss 8.8epss 0.60

    An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.

  • CVE-2021-30571CriAug 3, 2021
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.