VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 19 of 187
  • CVE-2025-36120HigAug 18, 2025
    risk 0.57cvss 8.8epss 0.00

    IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH session due to incorrect authorization checks to access resources.

  • CVE-2025-7773HigAug 14, 2025
    risk 0.57cvss epss 0.00

    A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number increments at an interval that correlates to the last two consecutive sign in session interval, making it predictable.

  • CVE-2025-42951HigAug 12, 2025
    risk 0.57cvss 8.8epss 0.00

    Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the corresponding API.�As a result , it has a high impact on the confidentiality, integrity, and availability of the application.

  • CVE-2025-53943HigJul 16, 2025
    risk 0.57cvss epss 0.00

    VoidBot Open-Source is a customizable Discord bot. VoidBot Open-Source versions 0.0.1 through 0.8.1 contain a vulnerability in the command handler where permission checks are not properly enforced for certain administrative commands. This allows users without the required roles…

  • CVE-2025-30751HigJul 15, 2025
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.27 and 23.4-23.8. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via…

  • CVE-2025-53895HigJul 15, 2025
    risk 0.57cvss 8.8epss 0.00

    ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2, 2.71.13, and 2.70.14, vulnerability in ZITADEL's session management API allows any authenticated user to update a session if they know its ID, due to a…

  • CVE-2025-53836CriJul 15, 2025
    risk 0.57cvss 9.9epss 0.01

    XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't…

  • CVE-2025-5822HigJun 25, 2025
    risk 0.57cvss 8.8epss 0.00

    Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An…

  • CVE-2025-48446HigJun 11, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.0.0 before 1.0.3.

  • CVE-2025-48445HigJun 11, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redirect): from 0.0.0 before 2.1.1.

  • CVE-2025-40670HigJun 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to /PC/frmGestionUser.aspx/updateUser.

  • CVE-2025-46265HigMay 7, 2025
    risk 0.57cvss 8.8epss 0.00

    On F5OS, an improper authorization vulnerability exists where remotely authenticated users (LDAP, RADIUS, TACACS+) may be authorized with higher privilege F5OS roles. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2025-46331CriApr 30, 2025
    risk 0.57cvss 9.8epss 0.00

    OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject…

  • CVE-2024-5705HigFeb 19, 2025
    risk 0.57cvss 8.8epss 0.00

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863)     Hitachi Vantara Pentaho Business…

  • CVE-2024-57434HigJan 31, 2025
    risk 0.57cvss 8.8epss 0.00

    macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super administrator.

  • CVE-2025-24500HigJan 30, 2025
    risk 0.57cvss epss 0.00

    The vulnerability allows an unauthenticated attacker to access information in PAM database.

  • CVE-2024-55225CriJan 9, 2025
    risk 0.57cvss 9.8epss 0.01

    An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.

  • CVE-2024-13282HigJan 9, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.

  • CVE-2024-56431CriDec 25, 2024
    risk 0.57cvss 9.8epss 0.02

    oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

  • CVE-2024-55662CriDec 12, 2024
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This…