VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 74 of 187
  • CVE-2024-47053HigFeb 26, 2025
    risk 0.43cvss 7.7epss 0.01

    This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw could allow unauthorized access to sensitive report data. * Improper Authorization: An authorization flaw exists in Mautic's API Authorization…

  • CVE-2025-21569MedJan 21, 2025
    risk 0.43cvss 6.6epss 0.00

    Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services). The supported version that is affected is 11.2.19.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to…

  • CVE-2024-10975HigNov 7, 2024
    risk 0.43cvss 7.7epss 0.00

    Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community…

  • CVE-2023-49734HigDec 19, 2023
    risk 0.43cvss 7.7epss 0.01

    An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.2, from…

  • CVE-2023-36826HigJul 25, 2023
    risk 0.43cvss 7.7epss 0.01

    Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a…

  • CVE-2023-35165MedJun 23, 2023
    risk 0.43cvss 6.6epss 0.01

    AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. In the packages `aws-cdk-lib` 2.0.0 until 2.80.0 and `@aws-cdk/aws-eks` 1.57.0 until 1.202.0, `eks.Cluster`…

  • CVE-2023-33254MedMay 21, 2023
    risk 0.43cvss 6.5epss 0.03

    There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication…

  • CVE-2023-30024MedApr 28, 2023
    risk 0.43cvss 6.6epss 0.00

    The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access. Attackers can exploit this by replacing the original software with a malicious version, leading to ransomware deployment on the…

  • CVE-2023-25575HigFeb 28, 2023
    risk 0.43cvss 7.7epss 0.01

    API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatform\Metadata\ApiProperty` attribute can be disclosed to unauthorized users. The problem affects most serialization…

  • CVE-2023-21560MedJan 10, 2023
    risk 0.43cvss 6.6epss 0.01

    Windows Boot Manager Security Feature Bypass Vulnerability

  • CVE-2021-26920MedJul 2, 2021
    risk 0.43cvss 6.5epss 0.10

    In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server…

  • CVE-2020-15278HigOct 28, 2020
    risk 0.43cvss 7.7epss 0.01

    Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit allows Discord users with a high privilege level within the guild to bypass hierarchy checks when the application is in a specific condition that is beyond that…

  • CVE-2020-15084HigJun 30, 2020
    risk 0.43cvss 7.7epss 0.01

    In express-jwt (NPM package) up and including version 5.3.3, the algorithms entry to be specified in the configuration is not being enforced. When algorithms is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass. You are…

  • CVE-2020-1796MedMar 20, 2020
    risk 0.43cvss 6.6epss 0.00

    There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product…

  • CVE-2020-5251HigMar 4, 2020
    risk 0.43cvss 7.7epss 0.01

    In parser-server before version 4.1.0, you can fetch all the users objects, by using regex in the NoSQL query. Using the NoSQL, you can use a regex on sessionToken and find valid accounts this way.

  • CVE-2019-0761MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.04

    A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of requests for specific URLs, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0768.

  • CVE-2018-5741MedJan 16, 2019
    risk 0.43cvss 6.5epss 0.03

    To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, depending on the key used…

  • CVE-2013-0335HigMar 22, 2013
    risk 0.43cvss 7.6epss 0.02

    OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

  • CVE-2026-55643HigAug 19, 2026
    risk 0.42cvss epss 0.00

    Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and…

  • CVE-2026-75480MedAug 17, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can query these endpoints to retrieve private memories, resources, skills, and secret…