VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 95 of 187
  • CVE-2025-2515HigDec 24, 2025
    risk 0.40cvss 7.2epss 0.00

    A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege…

  • CVE-2025-3586HigSep 1, 2025
    risk 0.40cvss 7.2epss 0.00

    In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 27 through update 42 (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy…

  • CVE-2025-30748MedJul 15, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2025-3838MedApr 21, 2025
    risk 0.40cvss epss 0.00

    An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db…

  • CVE-2025-21582MedApr 15, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-9098MedMar 20, 2025
    risk 0.40cvss 6.1epss 0.01

    In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing resources. This issue arises because the user creation endpoint does not restrict…

  • CVE-2025-21570MedJan 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login). The supported version that is affected is 8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2024-48540MedOct 24, 2024
    risk 0.40cvss 6.2epss 0.00

    Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.

  • CVE-2024-38425MedOct 7, 2024
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while sending implicit broadcast containing APP launch information.

  • CVE-2024-42423MedSep 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and…

  • CVE-2024-34651MedSep 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

  • CVE-2024-42062HigAug 7, 2024
    risk 0.40cvss 7.2epss 0.01

    CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys and use them for the purpose of API-based automation and integrations. Due to an access permission…

  • CVE-2024-25420HigMar 26, 2024
    risk 0.40cvss 7.2epss 0.01

    An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

  • CVE-2024-24966MedFeb 14, 2024
    risk 0.40cvss 6.2epss 0.00

    When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2023-3459HigJul 18, 2023
    risk 0.40cvss 7.2epss 0.01

    The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for…

  • CVE-2023-29656MedJul 6, 2023
    risk 0.40cvss 6.1epss 0.00

    An improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users to control "antigena" actions(block/unblock traffic) from the mobile application. This vulnerability could create a "shutdown", blocking all…

  • CVE-2023-28249MedApr 11, 2023
    risk 0.40cvss 6.2epss 0.01

    Windows Boot Manager Security Feature Bypass Vulnerability

  • CVE-2022-36103HigSep 13, 2022
    risk 0.40cvss 7.2epss 0.01

    Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepted into the Talos cluster. Due to improper validation of the request while signing a worker node CSR (certificate signing request) Talos control plane node…

  • CVE-2022-33718MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

  • CVE-2022-1132MedJul 23, 2022
    risk 0.40cvss 6.1epss 0.00

    Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local attacker to bypass navigation restrictions via physical access to the device.