VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 121 of 187
  • CVE-2025-64753MedNov 13, 2025
    risk 0.34cvss 5.3epss 0.00

    grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing hashes for versions of that document and receive a full list of changes between versions, even if those changes contained…

  • CVE-2025-11581MedOct 10, 2025
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit has been…

  • CVE-2025-54877MedAug 29, 2025
    risk 0.34cvss 5.3epss 0.00

    Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition versions before 16.10.99.1754050155 and Tuleap Enterprise Edition versions before 16.9-8 and before 16.10-5, an attacker can access to the…

  • CVE-2025-54554MedAug 4, 2025
    risk 0.34cvss 5.3epss 0.00

    tiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the underlying SQL queries and database structure.

  • CVE-2025-6003MedJun 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The WordPress Single Sign-On (SSO) plugin for WordPress is vulnerable to unauthorized access due to a misconfigured capability check on a function in all versions up to, and including, the *.5.3 versions of the plugin. This makes it possible for unauthenticated attackers to…

  • CVE-2025-3609MedMay 6, 2025
    risk 0.34cvss 5.3epss 0.00

    The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to the 'reales_user_signup_form' AJAX action not verifying if user registration is enabled, prior to registering a user. This makes it…

  • CVE-2025-43921MedApr 20, 2025
    risk 0.34cvss 5.3epss 0.00

    GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

  • CVE-2025-30209MedMar 31, 2025
    risk 0.34cvss 5.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition…

  • CVE-2021-41528MedFeb 7, 2025
    risk 0.34cvss epss 0.00

    An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to access the import / export functionality with low privileges.

  • CVE-2024-54488MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.01

    A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. Photos in the Hidden Photos Album may be viewed without authentication.

  • CVE-2025-21554MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2024-57681MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.01

    An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.

  • CVE-2024-57680MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.01

    An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.

  • CVE-2024-13302MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3.

  • CVE-2024-13290MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before 2.0.4.

  • CVE-2024-13266MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4.

  • CVE-2024-13257MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.

  • CVE-2024-8650MedDec 16, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

  • CVE-2024-8116MedDec 16, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

  • CVE-2024-11176MedNov 20, 2024
    risk 0.34cvss epss 0.00

    Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions.