VYPR

CWE-1390

Weak Authentication

ClassIncomplete

Description

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Hierarchy (View 1000)

CVEs mapped to this weakness (89)

page 1 of 5
  • CVE-2025-40554CriJan 28, 2026
    risk 0.68cvss 9.8epss 0.57

    SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

  • CVE-2025-40552CriJan 28, 2026
    risk 0.68cvss 9.8epss 0.50

    SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.

  • CVE-2025-30412CriFeb 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

  • CVE-2025-30411CriFeb 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.

  • CVE-2026-68067CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record…

  • CVE-2026-6274CriJun 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3…

  • CVE-2026-6886CriApr 23, 2026
    risk 0.64cvss 9.8epss 0.00

    Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.

  • CVE-2026-28710CriMar 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186.

  • CVE-2023-53894CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.01

    phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP…

  • CVE-2025-63807CriNov 20, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification…

  • CVE-2025-12871CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.

  • CVE-2025-12870CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.

  • CVE-2025-47889CriMay 14, 2025
    risk 0.64cvss 9.8epss 0.01

    In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames…

  • CVE-2025-39596CriApr 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects Quentn WP: from n/a through <= 1.2.8.

  • CVE-2024-54092CriApr 8, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial Edge Device Kit - arm64 V1.19 (All versions), Industrial Edge Device Kit - arm64 V1.20 (All versions < V1.20.2-1),…

  • CVE-2025-1387CriFeb 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.

  • CVE-2024-13239CriJan 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.

  • CVE-2023-49340CriMar 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.

  • CVE-2022-43400CriOct 21, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of Administrators group. This could allow…

  • CVE-2026-55040CriJul 14, 2026
    risk 0.59cvss 9.1epss 0.04

    Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.