VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,257)

page 94 of 213
  • CVE-2025-46544MedApr 25, 2025
    risk 0.42cvss 6.4epss 0.00

    In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.

  • CVE-2025-3475MedApr 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoofing.This issue affects WEB-T: from 0.0.0 before 1.1.0.

  • CVE-2025-31481HigApr 3, 2025
    risk 0.42cvss 7.5epss 0.00

    API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.

  • CVE-2024-55965MedMar 26, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development information of a workspace (specifically, a list of datasources in a workspace they're a member of). This information disclosure does not expose sensitive data…

  • CVE-2024-9159MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue arises because the function responsible for restarting the…

  • CVE-2024-10273MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.00

    In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for models does not have appropriate privilege checks, enabling low-privilege users to update models they should…

  • CVE-2025-29924HigMar 19, 2025
    risk 0.42cvss 7.5epss 0.00

    XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private information through the REST API - but could also be through another API - when a sub wiki is using "Prevent unregistered users to view…

  • CVE-2024-45081MedFeb 19, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to incorrect authorization checks.

  • CVE-2025-23054MedJan 28, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not allowed by their privilege level. Successful exploitation could allow an attacker to manipulate user…

  • CVE-2025-23053MedJan 28, 2025
    risk 0.42cvss 6.5epss 0.00

    A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

  • CVE-2023-50946MedJan 26, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism.

  • CVE-2024-42013MedJan 22, 2025
    risk 0.42cvss 6.4epss 0.00

    In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attacker with Windows administrative or debugging privileges can patch a binary in memory or on disk to bypass the password login requirement and gain full access…

  • CVE-2025-21560MedJan 21, 2025
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2024-57679MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.01

    An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.

  • CVE-2024-57678MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.

  • CVE-2024-57677MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.01

    An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.

  • CVE-2024-57676MedJan 16, 2025
    risk 0.42cvss 6.5epss 0.00

    An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G wlan service of the device via a crafted POST request.

  • CVE-2025-21403MedJan 14, 2025
    risk 0.42cvss 6.4epss 0.01

    On-Premises Data Gateway Information Disclosure Vulnerability

  • CVE-2024-56114MedJan 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit…

  • CVE-2024-39025HigDec 27, 2024
    risk 0.42cvss 7.5epss 0.00

    Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.