VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,803)

page 13 of 241
  • CVE-2026-23906CriFeb 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits anonymous bind   …

  • CVE-2025-37184CriJan 14, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor…

  • CVE-2026-22236CriJan 14, 2026
    risk 0.64cvss 9.8epss 0.00

    The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable APIs. Successful exploitation of this vulnerability…

  • CVE-2025-60534CriJan 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectively proxy requests in order to operate functionality on the web application without the need to authenticate with legitimate credentials.

  • CVE-2025-56333CriDec 29, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component

  • CVE-2025-67791CriDec 17, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise…

  • CVE-2025-12374CriDec 5, 2025
    risk 0.64cvss 9.8epss 0.01

    The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.44. This is due to the plugin not properly validating that…

  • CVE-2025-64055CriDec 3, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.

  • CVE-2025-63210CriNov 19, 2025
    risk 0.64cvss 9.8epss 0.01

    The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during…

  • CVE-2025-63207CriNov 19, 2025
    risk 0.64cvss 9.8epss 0.07

    The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User…

  • CVE-2025-43995CriOct 24, 2025
    risk 0.64cvss 9.8epss 0.01

    Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. Authentication Bypass in DSM…

  • CVE-2025-56447CriOct 22, 2025
    risk 0.64cvss 9.8epss 0.00

    TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

  • CVE-2025-41108CriOct 22, 2025
    risk 0.64cvss 9.8epss 0.00

    The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station, impersonating the control station (tablet) and gaining unauthorised full control of the robot. The absence of…

  • CVE-2025-60772CriOct 21, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to escalate privileges and lock out the legitimate administrator via crafted HTTP requests.

  • CVE-2025-9063CriOct 14, 2025
    risk 0.64cvss 9.8epss 0.00

    An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic…

  • CVE-2025-60306CriOct 10, 2025
    risk 0.64cvss 9.9epss 0.00

    code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.

  • CVE-2025-34186CriSep 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Because the binary…

  • CVE-2025-9994CriSep 9, 2025
    risk 0.64cvss 9.8epss 0.01

    The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access.

  • CVE-2025-52856CriAug 29, 2025
    risk 0.64cvss 9.8epss 0.01

    An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: VioStor 5.1.6 build 20250621…

  • CVE-2024-52786CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL.