VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 37 of 187
  • CVE-2025-24200MedKEVFeb 10, 2025
    risk 0.52cvss 6.1epss 0.04

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is…

  • CVE-2024-45261HigOct 24, 2024
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses…

  • CVE-2024-45260HigOct 24, 2024
    risk 0.52cvss 8.0epss 0.04

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.

  • CVE-2024-45160CriOct 9, 2024
    risk 0.52cvss 9.1epss 0.01

    Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).

  • CVE-2024-44667HigSep 10, 2024
    risk 0.52cvss 8.0epss 0.01

    Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.

  • CVE-2024-35187CriMay 16, 2024
    risk 0.52cvss 9.1epss 0.01

    Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, system services are run as a separate user…

  • CVE-2024-2378HigApr 30, 2024
    risk 0.52cvss 8.0epss 0.00

    A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privileges on af-fected installations.

  • CVE-2023-46244CriNov 7, 2023
    risk 0.52cvss 9.1epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to write a script in which any velocity content is executed with the right of any other document content author. Since this API…

  • CVE-2023-20269MedKEVSep 6, 2023
    risk 0.52cvss 5.0epss 0.22

    A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and…

  • CVE-2023-3484HigJul 21, 2023
    risk 0.52cvss 8.0epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain…

  • CVE-2023-23947CriFeb 16, 2023
    risk 0.52cvss 9.1epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one…

  • CVE-2022-47408CriDec 14, 2022
    risk 0.52cvss 9.1epss 0.01

    An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribing many people.

  • CVE-2022-39322CriOct 25, 2022
    risk 0.52cvss 9.1epss 0.01

    @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - are vulnerable to their…

  • CVE-2022-35924CriAug 2, 2022
    risk 0.52cvss 9.1epss 0.01

    NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker could forge a request that sent a comma-separated list of…

  • CVE-2021-24905HigMar 21, 2022
    risk 0.52cvss 8.0epss 0.01

    The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server.…

  • CVE-2022-0860CriMar 11, 2022
    risk 0.52cvss 9.1epss 0.02

    Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

  • CVE-2021-38598CriAug 23, 2021
    risk 0.52cvss 9.1epss 0.01

    OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to…

  • CVE-2020-13300HigSep 14, 2020
    risk 0.52cvss 8.0epss 0.01

    GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

  • CVE-2013-4985HigDec 27, 2019
    risk 0.52cvss 7.5epss 0.09

    Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream

  • CVE-2018-2494HigDec 11, 2018
    risk 0.52cvss 8.0epss 0.01

    Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform.