VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,735)

page 13 of 187
  • CVE-2024-53553CriJan 16, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.

  • CVE-2024-13281CriJan 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.

  • CVE-2024-13278CriJan 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.

  • CVE-2024-13277CriJan 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.

  • CVE-2024-13253CriJan 9, 2025
    risk 0.59cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.

  • CVE-2024-54662CriDec 17, 2024
    risk 0.59cvss 9.1epss 0.01

    Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving socksmethod.

  • CVE-2024-52732CriDec 2, 2024
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system being reused.

  • CVE-2024-44217CriOct 28, 2024
    risk 0.59cvss 9.1epss 0.00

    A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may fill in passwords after failing authentication.

  • CVE-2024-38002CriOct 22, 2024
    risk 0.59cvss 9.0epss 0.01

    The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which…

  • CVE-2024-48772CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48787CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48786CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48778CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48769CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via the firmware update process.

  • CVE-2024-6593CriSep 25, 2024
    risk 0.59cvss 9.1epss 0.01

    Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability…

  • CVE-2024-6592CriSep 25, 2024
    risk 0.59cvss 9.1epss 0.01

    An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications…

  • CVE-2024-42773CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.

  • CVE-2024-41110CriJul 24, 2024
    risk 0.59cvss 9.9epss 0.17

    Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base…

  • CVE-2024-1741CriApr 10, 2024
    risk 0.59cvss 9.1epss 0.01

    lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on…

  • CVE-2024-1740CriApr 10, 2024
    risk 0.59cvss 9.1epss 0.01

    In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an old authorization token. The lunary web application communicates with the server using an 'Authorization' token in…