VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,244)

page 142 of 213
  • CVE-2025-30209MedMar 31, 2025
    risk 0.34cvss 5.3epss 0.00

    Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition…

  • CVE-2021-41528MedFeb 7, 2025
    risk 0.34cvss —epss 0.00

    An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to access the import / export functionality with low privileges.

  • CVE-2024-54488MedJan 27, 2025
    risk 0.34cvss 5.3epss 0.01

    A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. Photos in the Hidden Photos Album may be viewed without authentication.

  • CVE-2025-21554MedJan 21, 2025
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2024-57681MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.01

    An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the agl service of the device via a crafted POST request.

  • CVE-2024-57680MedJan 16, 2025
    risk 0.34cvss 5.3epss 0.01

    An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the port trigger of the device via a crafted POST request.

  • CVE-2024-13302MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3.

  • CVE-2024-13290MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before 2.0.4.

  • CVE-2024-13266MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4.

  • CVE-2024-13257MedJan 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.

  • CVE-2024-8650MedDec 16, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

  • CVE-2024-8116MedDec 16, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

  • CVE-2024-11176MedNov 20, 2024
    risk 0.34cvss —epss 0.00

    Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions.

  • CVE-2024-9902MedNov 6, 2024
    risk 0.34cvss 6.3epss 0.00

    A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home…

  • CVE-2024-5816MedJul 16, 2024
    risk 0.34cvss 5.3epss 0.01

    An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped user access token. This was only exploitable in public repositories while private repositories were not…

  • CVE-2024-37154MedJun 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects employees and grantees who have funds managed via `ClawbackVestingAccount`. This affects 18.1.0 and earlier.

  • CVE-2024-21120MedApr 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…

  • CVE-2024-27288MedMar 6, 2024
    risk 0.34cvss 6.3epss 0.00

    1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to the console page. The vulnerability has been fixed in v1.10.1-lts. There are no known workarounds.

  • CVE-2023-6963MedFeb 5, 2024
    risk 0.34cvss 5.3epss 0.01

    The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to bypass the Captcha Verification of the Contact Form block by omitting 'g-recaptcha-response' from…

  • CVE-2023-44401MedJan 23, 2024
    risk 0.34cvss 5.3epss 0.00

    The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is…