VYPR

CWE-1390

Weak Authentication

ClassIncomplete

Description

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

Hierarchy (View 1000)

CVEs mapped to this weakness (89)

page 5 of 5
  • CVE-2024-8322MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.01

    Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.

  • CVE-2024-5891MedJun 12, 2024
    risk 0.27cvss 4.2epss 0.00

    A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was created. This issue is limited to authentication and not…

  • CVE-2024-29038MedJun 28, 2024
    risk 0.21cvss 4.3epss 0.00

    tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

  • CVE-2023-41900LowSep 15, 2023
    risk 0.16cvss 3.5epss 0.01

    Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides to revoke an already…

  • CVE-2025-29991LowApr 3, 2025
    risk 0.14cvss 2.2epss 0.00

    Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.

  • CVE-2026-59554HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

  • CVE-2026-50756HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

  • CVE-2026-57352MedJul 2, 2026
    risk 0.00cvss 4.8epss 0.00

    Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.

  • CVE-2024-0822HigJan 25, 2024
    risk 0.00cvss 7.5epss 0.01

    An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.