VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (5,090)

page 164 of 255
  • CVE-2025-4015MedApr 28, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of the file novel-system/src/main/java/com/java2nb/system/controller/SessionController.java. The…

  • CVE-2025-2771MedApr 23, 2025
    risk 0.35cvss 5.3epss 0.01

    BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2025-3268MedApr 4, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentication. The attack can be initiated…

  • CVE-2025-2339MedMar 16, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part of the file /%61dmin/api/logs. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2024-38426MedMar 3, 2025
    risk 0.35cvss 5.4epss 0.00

    While processing the authentication message in UE, improper authentication may lead to information disclosure.

  • CVE-2025-27112MedFeb 24, 2025
    risk 0.35cvss 6.5epss 0.01

    Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subsonic API endpoints, a flaw in the authentication check process allows an attacker to specify any arbitrary username that does not…

  • CVE-2025-1231MedFeb 11, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due to crash in the password reset functionality.

  • CVE-2025-0604MedJan 22, 2025
    risk 0.35cvss 5.4epss 0.01

    A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expired or disabled to regain access in…

  • CVE-2024-13309MedJan 9, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.

  • CVE-2024-10511MedDec 11, 2024
    risk 0.35cvss 5.3epss 0.01

    CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local network repeatedly requests the /accessdenied URL.

  • CVE-2024-11671MedNov 25, 2024
    risk 0.35cvss 5.4epss 0.01

    Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.

  • CVE-2024-7870MedSep 4, 2024
    risk 0.35cvss 6.5epss 0.00

    The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 and 10.4.2, respectively, through publicly exposed log files. This makes it…

  • CVE-2024-43409MedAug 20, 2024
    risk 0.35cvss 6.5epss 0.00

    Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains…

  • CVE-2024-40794MedJul 29, 2024
    risk 0.35cvss 5.3epss 0.01

    This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing tabs may be accessed without authentication.

  • CVE-2024-32868MedApr 26, 2024
    risk 0.35cvss 6.5epss 0.00

    ZITADEL provides users the possibility to use Time-based One-Time-Password (TOTP) and One-Time-Password (OTP) through SMS and Email. While ZITADEL already gives administrators the option to define a `Lockout Policy` with a maximum amount of failed password check attempts, there…

  • CVE-2023-5675MedApr 25, 2024
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in Quarkus. When a Quarkus RestEasy Classic or Reactive JAX-RS endpoint has its methods declared in the abstract Java class or customized by Quarkus extensions using the annotation processor, the authorization of these methods will not be enforced if it is…

  • CVE-2023-39196MedFeb 7, 2024
    risk 0.35cvss 5.3epss 0.01

    Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata internal to the Storage Container Manager service without proper authentication. The attacker is not allowed to do any modification within the Ozone Storage…

  • CVE-2024-23647MedJan 30, 2024
    risk 0.35cvss 6.5epss 0.01

    Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds the code_verifier parameter to the…

  • CVE-2023-7079MedDec 29, 2023
    risk 0.35cvss 6.4epss 0.01

    Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network into opening a malicious website could also…

  • CVE-2023-6907MedDec 18, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /file-manager/delete.php of the component Deletion Interface. The manipulation of the argument file leads…