VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,734)

page 4 of 187
  • CVE-2019-25237CriDec 24, 2025
    risk 0.64cvss 9.8epss 0.00

    V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod'…

  • CVE-2025-55469CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

  • CVE-2025-41346CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.00

    Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality,…

  • CVE-2025-10611CriOct 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation. Successful exploitation of this vulnerability could lead to a…

  • CVE-2025-36157CriAug 24, 2025
    risk 0.64cvss 9.8epss 0.01

    IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions.

  • CVE-2025-49825CriJun 17, 2025
    risk 0.64cvss 9.8epss 0.08

    Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.

  • CVE-2025-20674CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202;…

  • CVE-2024-6914CriMay 22, 2025
    risk 0.64cvss 9.8epss 0.01

    An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account recovery-related SOAP admin service. A malicious actor can exploit this vulnerability to reset the password of any user account, leading to a complete account…

  • CVE-2025-29827CriMay 8, 2025
    risk 0.64cvss 9.9epss 0.01

    Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-24233CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to read or write to protected files.

  • CVE-2025-27138CriMar 13, 2025
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which may cause the risk of unauthorized access. The vulnerability has been fixed in…

  • CVE-2025-27645CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Insecure Extension Installation by Trusting HTTP Permission Methods on the Server Side V-2024-005.

  • CVE-2025-21556CriJan 21, 2025
    risk 0.64cvss 9.9epss 0.01

    Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2024-57032CriJan 17, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.

  • CVE-2024-13258CriJan 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.

  • CVE-2024-31695CriNov 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attackers to bypass authentication when adding a new fingerprint.

  • CVE-2024-48176CriNov 5, 2024
    risk 0.64cvss 9.8epss 0.00

    Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.

  • CVE-2024-48237CriOct 25, 2024
    risk 0.64cvss 9.8epss 0.00

    WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.

  • CVE-2024-48784CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.01

    An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-7108CriSep 26, 2024
    risk 0.64cvss 9.8epss 0.00

    Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CyberMath: before CYBM.240816253.