VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 124 of 187
  • CVE-2025-69417MedJan 2, 2026
    risk 0.33cvss 5.0epss 0.00

    In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.

  • CVE-2025-69416MedJan 2, 2026
    risk 0.33cvss 5.0epss 0.00

    In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.

  • CVE-2025-62647MedOct 17, 2025
    risk 0.33cvss 5.0epss 0.00

    The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning a JWT that can be used to call an API to return a signed AWS upload URL, for any store's path.

  • CVE-2025-52918MedJun 21, 2025
    risk 0.33cvss 5.0epss 0.00

    Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.

  • CVE-2025-1418MedMay 21, 2025
    risk 0.33cvss epss 0.00

    A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their usage in connected devices).    This…

  • CVE-2025-1415MedMay 21, 2025
    risk 0.33cvss epss 0.00

    A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Device Management), as well as details of the devices like their UUIDs needed for exploitation of CVE-2025-1416. In order to perform the attack, one has to know…

  • CVE-2025-24099MedJan 30, 2025
    risk 0.33cvss 5.1epss 0.00

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker may be able to elevate their privileges.

  • CVE-2024-48936MedOct 28, 2024
    risk 0.33cvss 5.0epss 0.00

    SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled…

  • CVE-2024-29892MedMar 27, 2024
    risk 0.33cvss 6.1epss 0.01

    ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by ZITADEL. For example it would be possible to set the claim `urn:zitadel:iam:user:resourceowner:name`. To…

  • CVE-2024-24779MedFeb 28, 2024
    risk 0.33cvss 5.0epss 0.01

    Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data.…

  • CVE-2023-32967MedFeb 2, 2024
    risk 0.33cvss 5.0epss 0.00

    An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected. We have…

  • CVE-2023-27523MedSep 6, 2023
    risk 0.33cvss 5.0epss 0.01

    Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.

  • CVE-2023-3114MedJun 22, 2023
    risk 0.33cvss 5.0epss 0.00

    Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the workspace to be targeted by unauthorized agents. This authorization flaw could potentially allow a workspace to access resources from a separate, higher-privileged…

  • CVE-2022-45128MedMay 10, 2023
    risk 0.33cvss 5.0epss 0.00

    Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2022-43465MedMay 10, 2023
    risk 0.33cvss 5.0epss 0.00

    Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2022-41610MedMay 10, 2023
    risk 0.33cvss 5.0epss 0.00

    Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2022-4315MedMar 8, 2023
    risk 0.33cvss 5.0epss 0.01

    An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.

  • CVE-2023-21424MedFeb 9, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.

  • CVE-2023-21423MedFeb 9, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.

  • CVE-2021-20290MedMar 25, 2022
    risk 0.33cvss 6.1epss 0.00

    An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources…