VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 159 of 255
  • CVE-2026-4349MedMar 17, 2026
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the file /connect/authorize of the component Token Renewal Endpoint. This manipulation of the argument id_token_hint causes improper authentication. It is…

  • CVE-2026-3192MedFeb 25, 2026
    risk 0.36cvss 5.6epss 0.01

    A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of the file rpc_server_base.py of the component RPC Credential Handler. The manipulation leads to improper authentication. The attack is possible to be carried out…

  • CVE-2026-20655MedFeb 11, 2026
    risk 0.36cvss 5.5epss 0.00

    An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

  • CVE-2026-1203MedJan 20, 2026
    risk 0.36cvss 5.6epss 0.01

    A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crmeb/app/services/user/LoginServices.php of the component JSON Token Handler. Executing a manipulation of the argument uid can lead to improper authentication.…

  • CVE-2025-6533MedJun 24, 2025
    risk 0.36cvss 5.6epss 0.01

    A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginController.java of the component CATCHA…

  • CVE-2025-5149MedMay 25, 2025
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the file /index.php?articleadmin/getallcon of the component Login. The manipulation of the argument uid leads to improper…

  • CVE-2025-2572MedApr 14, 2025
    risk 0.36cvss 5.6epss 0.00

    In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.

  • CVE-2025-26475MedMar 19, 2025
    risk 0.36cvss 5.5epss 0.00

    Dell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.26, Enables Live-Restore setting which enhances security by keeping containers running during daemon restarts, reducing attack exposure, preventing accidental misconfigurations, and ensuring security controls…

  • CVE-2024-13111MedJan 2, 2025
    risk 0.36cvss 5.6epss 0.01

    A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the…

  • CVE-2024-50339MedDec 12, 2024
    risk 0.36cvss 5.3epss 0.19

    GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this issue.

  • CVE-2023-46172MedMar 7, 2024
    risk 0.36cvss 5.6epss 0.01

    IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass authentication restrictions for authorized user. IBM X-Force ID: 269409.

  • CVE-2023-47256MedFeb 1, 2024
    risk 0.36cvss 5.5epss 0.00

    ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

  • CVE-2023-42935MedJan 23, 2024
    risk 0.36cvss 5.5epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.

  • CVE-2023-7211MedJan 7, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipulation leads to reliance on ip address for authentication. The attack can be initiated remotely. The…

  • CVE-2023-31292MedDec 29, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) 6.3.8.6 (#718), allows local attackers to obtain sensitive information and bypass authentication via "Back Button Refresh" attack.

  • CVE-2023-43582MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

  • CVE-2023-26455MedNov 2, 2023
    risk 0.36cvss 5.6epss 0.00

    RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated…

  • CVE-2023-36724MedOct 10, 2023
    risk 0.36cvss 5.5epss 0.01

    Windows Power Management Service Information Disclosure Vulnerability

  • CVE-2023-41751MedAug 31, 2023
    risk 0.36cvss 5.5epss 0.00

    Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) before build 32047.

  • CVE-2023-27538MedMar 30, 2023
    risk 0.36cvss 5.5epss 0.01

    An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse…