VYPR

CWE-1390

Weak Authentication

ClassIncomplete

Description

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Hierarchy (View 1000)

CVEs mapped to this weakness (96)

page 4 of 5
  • CVE-2024-38239HigSep 10, 2024
    risk 0.47cvss 7.2epss 0.02

    Windows Kerberos Elevation of Privilege Vulnerability

  • CVE-2025-7326HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.01

    Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon…

  • CVE-2025-24070HigMar 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-1293HigFeb 20, 2025
    risk 0.46cvss 8.2epss 0.00

    Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.

  • CVE-2025-30468MedSep 15, 2025
    risk 0.42cvss 6.5epss 0.00

    This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessed without authentication.

  • CVE-2025-47995MedJul 18, 2025
    risk 0.42cvss 6.5epss 0.01

    Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-32885MedMay 1, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom message (into existing v1 networks) with any GID and Callsign via a software defined radio. This can be exploited if the device is being used in…

  • CVE-2025-26635MedApr 8, 2025
    risk 0.42cvss 6.5epss 0.01

    Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.

  • CVE-2025-21552MedJan 21, 2025
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2024-47127MedSep 26, 2024
    risk 0.42cvss 6.5epss 0.00

    In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an unencrypted…

  • CVE-2024-41722MedSep 26, 2024
    risk 0.42cvss 6.5epss 0.00

    In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the device is being used in an …

  • CVE-2024-6580MedJul 8, 2024
    risk 0.42cvss 6.5epss 0.00

    The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user access without…

  • CVE-2023-4094MedSep 19, 2023
    risk 0.42cvss 6.5epss 0.01

    ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the…

  • CVE-2023-24890MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft OneDrive for iOS Security Feature Bypass Vulnerability

  • CVE-2024-45551MedApr 7, 2025
    risk 0.40cvss 6.2epss 0.00

    Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.

  • CVE-2026-59135MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

  • CVE-2025-62844MedMar 20, 2026
    risk 0.36cvss 5.5epss 0.00

    A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: QuRouter 2.6.2.007 and later

  • CVE-2026-44476MedAug 25, 2026
    risk 0.34cvss —epss 0.01

    Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its…

  • CVE-2026-32497MedMar 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45.

  • CVE-2025-47479MedJul 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This issue affects WP Compress: from n/a through <= 6.30.30.