VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,735)

page 15 of 187
  • CVE-2021-26040CriAug 24, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Joomla! 4.0.0. The media manager does not correctly check the user's permissions before executing a file deletion command.

  • CVE-2021-20538CriMay 10, 2021
    risk 0.59cvss 9.1epss 0.01

    IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 could allow a user to obtain sensitive information or perform actions they should not have access to due to incorrect authorization mechanisms. IBM X-Force ID: 198919.

  • CVE-2020-29020CriMar 5, 2021
    risk 0.59cvss 9.1epss 0.02

    Improper Access Control vulnerability in web service of Secomea SiteManager allows remote attacker to access the web UI from the internet using the configured credentials. This issue affects: Secomea SiteManager All versions prior to 9.4.620527004 on Hardware.

  • CVE-2013-1350CriJan 30, 2020
    risk 0.59cvss 9.1epss 0.02

    Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities

  • CVE-2019-19597HigDec 5, 2019
    risk 0.59cvss 8.8epss 0.21

    D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.

  • CVE-2010-2548CriOct 31, 2019
    risk 0.59cvss 9.1epss 0.02

    IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.

  • CVE-2019-7258HigJul 2, 2019
    risk 0.59cvss 8.8epss 0.20

    Linear eMerge E3-Series devices allow Privilege Escalation.

  • CVE-2018-1245CriJul 13, 2018
    risk 0.59cvss 9.0epss 0.03

    RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0 contains an authorization bypass vulnerability within the workflow architect component (ACM). A remote authenticated malicious user with non-admin privileges could potentially bypass the Java Security…

  • CVE-2018-7245CriApr 18, 2018
    risk 0.59cvss 9.1epss 0.01

    An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and…

  • CVE-2026-27604CriJun 23, 2026
    risk 0.58cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the…

  • CVE-2026-46595CriMay 22, 2026
    risk 0.58cvss 10.0epss 0.01

    Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.

  • CVE-2025-20701HigAug 4, 2025
    risk 0.58cvss 8.8epss 0.07

    In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-23924CriFeb 1, 2023
    risk 0.58cvss 10.0epss 0.04

    Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the…

  • CVE-2022-24783CriMar 25, 2022
    risk 0.58cvss 10.0epss 0.01

    Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell…

  • CVE-2021-37705CriAug 13, 2021
    risk 0.58cvss 10.0epss 0.02

    OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allows an authenticated user from any Azure Active Directory tenant to make authorized API calls to a vulnerable OneFuzz instance. To…

  • CVE-2020-35682HigMar 13, 2021
    risk 0.58cvss 8.8epss 0.07

    Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).

  • CVE-2020-3229HigJun 3, 2020
    risk 0.58cvss 8.8epss 0.05

    A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerability is due to incorrect handling of RBAC…

  • CVE-2020-10786HigApr 21, 2020
    risk 0.58cvss 8.8epss 0.05

    A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.

  • CVE-2019-19681HigDec 26, 2019
    risk 0.58cvss 8.8epss 0.05

    Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in…

  • CVE-2019-5602HigJul 3, 2019
    risk 0.58cvss 8.8epss 0.04

    In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the cdrom driver allows users with read access to the cdrom device to arbitrarily overwrite…