VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 35 of 187
  • CVE-2021-3337HigJan 28, 2021
    risk 0.53cvss 7.5epss 0.11

    The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

  • CVE-2021-21013HigJan 13, 2021
    risk 0.53cvss 8.1epss 0.03

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sensitive information disclosure and update arbitrary…

  • CVE-2017-18884HigJun 19, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth application with personal access tokens.

  • CVE-2020-10510HigMar 27, 2020
    risk 0.53cvss 8.1epss 0.01

    Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a specific URL, access unauthorized functionality and data.

  • CVE-2014-7914HigFeb 21, 2020
    risk 0.53cvss 8.1epss 0.00

    btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.

  • CVE-2019-7639HigFeb 8, 2019
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsissh/sshd_config file, logins succeed with a valid username and an incorrect password, even though a failure entry is recorded in the /var/log/messages file.

  • CVE-2018-15465HigDec 24, 2018
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileged actions by using the web management interface. The vulnerability is due to…

  • CVE-2018-10925HigAug 9, 2018
    risk 0.53cvss 8.1epss 0.02

    It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read…

  • CVE-2018-1000197HigJun 5, 2018
    risk 0.53cvss 8.1epss 0.01

    An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Black Duck Hub plugin configuration.

  • CVE-2017-12118HigJan 19, 2018
    risk 0.53cvss 8.1epss 0.02

    An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). An attacker can send JSON to trigger this vulnerability.

  • CVE-2017-12116HigJan 19, 2018
    risk 0.53cvss 8.1epss 0.02

    An exploitable improper authorization vulnerability exists in miner_setGasPrice API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can…

  • CVE-2017-12113HigJan 19, 2018
    risk 0.53cvss 8.1epss 0.01

    An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can…

  • CVE-2017-12117HigJan 19, 2018
    risk 0.53cvss 8.1epss 0.01

    An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can send…

  • CVE-2017-12115HigJan 19, 2018
    risk 0.53cvss 8.1epss 0.02

    An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass.

  • CVE-2017-12112HigJan 19, 2018
    risk 0.53cvss 8.1epss 0.01

    An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can cause an access to the restricted functionality resulting in authorization bypass. An attacker can…

  • CVE-2018-0110HigJan 18, 2018
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has been disabled via the web application. The vulnerability is due to a design flaw in Cisco WebEx Meetings Server, which would not…

  • CVE-2026-59689HigJul 27, 2026
    risk 0.52cvss 8.0epss 0.00

    An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting…

  • CVE-2026-53512CriJul 15, 2026
    risk 0.52cvss 9.1epss 0.00

    Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without…

  • CVE-2026-20706CriJul 3, 2026
    risk 0.52cvss 9.1epss 0.00

    Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.

  • CVE-2026-32967CriJun 17, 2026
    risk 0.52cvss 9.1epss 0.00

    Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.