VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 136 of 187
  • CVE-2025-11439MedOct 8, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/integrations. Performing manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit has been made public and…

  • CVE-2025-49641MedOct 3, 2025
    risk 0.28cvss 4.3epss 0.00

    A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.

  • CVE-2025-11239MedOct 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user's team. Starting with KNIME Business Hub 1.16.0 only metadata of jobs is shown to team members. Only the creator of a job can see all information including in-…

  • CVE-2025-59824MedSep 24, 2025
    risk 0.28cvss 5.4epss 0.00

    Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escape. Omni and each Talos machine establish a peer-to-peer (P2P) SideroLink connection using WireGuard to mutually authenticate and…

  • CVE-2025-43806MedSep 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the…

  • CVE-2025-58134MedSep 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.

  • CVE-2025-9835MedSep 2, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2025-1501MedAug 26, 2025
    risk 0.28cvss 4.3epss 0.00

    An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can…

  • CVE-2025-9228MedAug 20, 2025
    risk 0.28cvss 4.3epss 0.00

    MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowing low-privilege users to create notes which are intended only for administrative users.

  • CVE-2025-20332MedAug 6, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An…

  • CVE-2025-53902MedJul 29, 2025
    risk 0.28cvss 4.3epss 0.00

    Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1752585665 and Tuleap Enterprise Edition prior to 16.8-6 and 16.9-5, users may potentially access confidential…

  • CVE-2025-54533MedJul 28, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration

  • CVE-2025-54532MedJul 28, 2025
    risk 0.28cvss 4.3epss 0.00

    In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies

  • CVE-2025-54596MedJul 25, 2025
    risk 0.28cvss 4.3epss 0.00

    Abnormal Security /v1.0/rbac/users_v2/{USER_ID}/ before 2025-02-19 allows downgrading the privileges of other user accounts.

  • CVE-2025-0765MedJul 24, 2025
    risk 0.28cvss 4.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

  • CVE-2025-6981MedJul 15, 2025
    risk 0.28cvss 4.3epss 0.00

    An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor accounts when the Contractors API feature was enabled. The Contractors API is a rarely-enabled feature in private preview. This vulnerability…

  • CVE-2025-30747MedJul 15, 2025
    risk 0.28cvss 4.3epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2025-3396MedJul 10, 2025
    risk 0.28cvss 4.3epss 0.00

    An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project owners to bypass group-level forking restrictions by manipulating API requests.

  • CVE-2025-20300MedJul 7, 2025
    risk 0.28cvss 4.3epss 0.00

    In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.112, and 9.2.2406.119, a low-privileged user that does not hold the "admin" or "power" Splunk roles, and has read-only access to a specific alert,…

  • CVE-2025-46702MedJun 30, 2025
    risk 0.28cvss 5.4epss 0.00

    Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions…