VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 20 of 187
  • CVE-2024-55579HigDec 9, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2024 Patch 10, February…

  • CVE-2024-42452HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges.…

  • CVE-2024-53937HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNET service is enabled by default with admin/admin as default credentials and is exposed over the LAN. The allows attackers to execute arbitrary commands with…

  • CVE-2024-53941HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default Wi-Fi PSK value via the last 4 octets of the BSSID.

  • CVE-2024-54124HigNov 29, 2024
    risk 0.57cvss 8.8epss 0.00

    In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.

  • CVE-2024-51426HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the _transfer function. NOTE: this is disputed by third parties because the impact is limited to function calls.

  • CVE-2024-51425HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact. NOTE: this is disputed by third parties because the impact is limited to function calls.

  • CVE-2022-30358HigOct 25, 2024
    risk 0.57cvss 8.8epss 0.01

    OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required.

  • CVE-2024-41617CriOct 24, 2024
    risk 0.57cvss 9.8epss 0.01

    Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated…

  • CVE-2024-8606HigSep 23, 2024
    risk 0.57cvss 8.8epss 0.00

    Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication

  • CVE-2024-45587HigSep 3, 2024
    risk 0.57cvss 8.8epss 0.00

    This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module of vulnerable application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through…

  • CVE-2024-45586HigSep 3, 2024
    risk 0.57cvss 8.8epss 0.00

    This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platforms (version 2.0.0.1_P160). An authenticated remote attacker could exploit this vulnerability by manipulating parameters through…

  • CVE-2024-31842HigAug 20, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser's history, passed through Referers to other web sites, stored in web logs, or…

  • CVE-2024-44076CriAug 19, 2024
    risk 0.57cvss 9.8epss 0.01

    In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.

  • CVE-2024-41939HigAug 13, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an authenticated attacker to bypass the checks and elevate their privileges on the application.

  • CVE-2024-7265HigAug 7, 2024
    risk 0.57cvss 8.8epss 0.00

    Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any user, including root user, which could lead to privilege escalation. This issue affects EZD RP: from 15…

  • CVE-2024-7062HigJul 26, 2024
    risk 0.57cvss 8.8epss 0.00

    Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, it is possible to execute…

  • CVE-2024-31970HigJul 24, 2024
    risk 0.57cvss 8.8epss 0.01

    AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the Internet. During a window of time when the device is being set up, it uses a default username and password combination…

  • CVE-2024-37905HigJun 28, 2024
    risk 0.57cvss 8.8epss 0.01

    authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik…

  • CVE-2024-38369CriJun 24, 2024
    risk 0.57cvss 9.9epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of a document included using `{{include reference="targetdocument"/}}` is executed with the right of the includer and not with the right of its author. This means…