VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 61 of 187
  • CVE-2025-8435HigAug 1, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin-control.php. The manipulation of the argument ID leads to missing authorization. The attack can…

  • CVE-2025-8434HigAug 1, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is an unknown function of the file /admin.php. The manipulation of the argument ID leads to missing authorization. It is possible to launch the attack remotely.…

  • CVE-2025-49536HigJul 8, 2025
    risk 0.47cvss 7.3epss 0.00

    ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access.…

  • CVE-2025-3260HigJun 2, 2025
    risk 0.47cvss 8.3epss 0.01

    A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders…

  • CVE-2025-48881HigMay 30, 2025
    risk 0.47cvss 8.3epss 0.00

    Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12.0.0.RELEASE to 12.12.0.RELEASE, all objects for which an object-management configuration exists can be listed, viewed, edited, created or deleted by…

  • CVE-2025-4646HigMay 13, 2025
    risk 0.47cvss 7.2epss 0.00

    Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.

  • CVE-2025-3963HigApr 27, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue affects some unknown processing of the file /admin/article/list of the component Background Interface. The manipulation leads to missing authorization. The…

  • CVE-2025-3960HigApr 27, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /allreaders.html of the component Background Interface. The manipulation leads to missing authorization. The attack…

  • CVE-2024-10275HigMar 20, 2025
    risk 0.47cvss 7.3epss 0.00

    In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change the permissions of existing users to include billing permissions. This can lead to a privilege escalation scenario where an…

  • CVE-2024-23929HigJan 31, 2025
    risk 0.47cvss 7.3epss 0.00

    This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw…

  • CVE-2024-13291HigJan 9, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.

  • CVE-2024-21083HigApr 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Script Engine). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise…

  • CVE-2024-21735HigJan 9, 2024
    risk 0.47cvss 7.3epss 0.00

    SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This could allow an attacker with high privileges to perform unintended actions, resulting in escalation of privileges,…

  • CVE-2023-50732HigDec 21, 2023
    risk 0.47cvss 8.3epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.

  • CVE-2022-47874MedMay 2, 2023
    risk 0.47cvss 6.5epss 0.21

    Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of database connections via class 'com.jedox.etl.mngr.Connections' and method 'getGlobalConnection'.

  • CVE-2023-23192HigMar 23, 2023
    risk 0.47cvss 7.2epss 0.01

    IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.

  • CVE-2023-24029HigFeb 3, 2023
    risk 0.47cvss 7.2epss 0.01

    In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to insufficient authorization controls applied on user modification workflows.

  • CVE-2022-4811HigDec 28, 2022
    risk 0.47cvss 8.3epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.

  • CVE-2022-23741HigDec 14, 2022
    risk 0.47cvss 7.2epss 0.01

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This vulnerability…

  • CVE-2022-2354HigAug 15, 2022
    risk 0.47cvss 7.2epss 0.01

    The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the server in multisite installations, where only super-administrators should.