VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,171)

page 42 of 209
  • CVE-2023-20269MedKEVSep 6, 2023
    risk 0.52cvss 5.0epss 0.25

    A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and…

  • CVE-2023-3484HigJul 21, 2023
    risk 0.52cvss 8.0epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain…

  • CVE-2023-23947CriFeb 16, 2023
    risk 0.52cvss 9.1epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one…

  • CVE-2022-47408CriDec 14, 2022
    risk 0.52cvss 9.1epss 0.01

    An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribing many people.

  • CVE-2022-39322CriOct 25, 2022
    risk 0.52cvss 9.1epss 0.01

    @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - are vulnerable to their…

  • CVE-2022-35924CriAug 2, 2022
    risk 0.52cvss 9.1epss 0.01

    NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker could forge a request that sent a comma-separated list of…

  • CVE-2021-24905HigMar 21, 2022
    risk 0.52cvss 8.0epss 0.01

    The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server.…

  • CVE-2022-0860CriMar 11, 2022
    risk 0.52cvss 9.1epss 0.02

    Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

  • CVE-2021-38598CriAug 23, 2021
    risk 0.52cvss 9.1epss 0.01

    OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to…

  • CVE-2020-13300HigSep 14, 2020
    risk 0.52cvss 8.0epss 0.01

    GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.

  • CVE-2013-4985HigDec 27, 2019
    risk 0.52cvss 7.5epss 0.09

    Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream

  • CVE-2018-2494HigDec 11, 2018
    risk 0.52cvss 8.0epss 0.01

    Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform.

  • CVE-2026-28663HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-28620HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    In multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-17063HigAug 19, 2026
    risk 0.51cvss 7.9epss 0.00

    IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can access and disrupt host…

  • CVE-2026-69278HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-61925HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25652HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction.

  • CVE-2026-43947HigJul 21, 2026
    risk 0.51cvss —epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Code Execution vulnerability when `secureEnabled` is set to `true`. The `POST /api/runscript` endpoint checks authorization against the stored script's…

  • CVE-2026-43945HigJul 21, 2026
    risk 0.51cvss —epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state…