VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,803)

page 15 of 241
  • CVE-2025-30430CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. Password autofill may fill in passwords after failing authentication.

  • CVE-2024-13804CriMar 30, 2025
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated RCE in HPE Insight Cluster Management Utility

  • CVE-2025-2859CriMar 28, 2025
    risk 0.64cvss 9.8epss 0.00

    An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.

  • CVE-2025-30361CriMar 27, 2025
    risk 0.64cvss 9.8epss 0.01

    WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to change a user's password without verifying the old password. This issue exists in the control.php endpoint and allows unauthorized…

  • CVE-2025-27138CriMar 13, 2025
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw in the authentication in the io.dataease.auth.filter.TokenFilter class, which may cause the risk of unauthorized access. The vulnerability has been fixed in…

  • CVE-2024-56336CriMar 11, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0 or SZVSN and the FS number is 02). The affected device contains an unlocked bootloader. This security oversight enables attackers to inject malicious code, or…

  • CVE-2025-27672CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-0016.

  • CVE-2025-27641CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-2024-009.

  • CVE-2025-0637CriJan 23, 2025
    risk 0.64cvss 9.8epss 0.00

    It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to access private areas and/or areas intended for other roles. The…

  • CVE-2025-0070CriJan 14, 2025
    risk 0.64cvss 9.9epss 0.01

    SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential…

  • CVE-2024-12264CriJan 7, 2025
    risk 0.64cvss 9.8epss 0.01

    The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost REST API endpoints not properly verifying a user's…

  • CVE-2024-1610CriDec 18, 2024
    risk 0.64cvss 9.8epss 0.01

    In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.

  • CVE-2024-12287CriDec 18, 2024
    risk 0.64cvss 9.8epss 0.01

    The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers…

  • CVE-2024-11015CriDec 12, 2024
    risk 0.64cvss 9.8epss 0.01

    The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the 'authenticate_user' user function not implementing sufficient null value checks when setting the access token and user information.…

  • CVE-2024-50478CriOct 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.

  • CVE-2024-7763CriOct 24, 2024
    risk 0.64cvss 9.8epss 0.01

    In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.

  • CVE-2020-36832CriOct 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it possible for unauthenticated attackers to login as any user, including the site administrator with a default user ID of 1, via…

  • CVE-2024-45115CriOct 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within…

  • CVE-2024-41798CriOct 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative access via Modbus TCP interface. Attackers with access to the Modbus TCP interface could easily bypass this protection by…

  • CVE-2024-34399CriSep 18, 2024
    risk 0.64cvss 9.8epss 0.01

    **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer supported by the maintainer…