VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 201 of 241
  • CVE-2025-54573MedJul 30, 2025
    risk 0.00cvss 4.3epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP Authentication. As a result, users could create accounts using fake email addresses and use the…

  • CVE-2025-52553CriJun 27, 2025
    risk 0.00cvss 9.6epss 0.00

    authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for the session of the user who authorized the…

  • CVE-2025-49591CriJun 18, 2025
    risk 0.00cvss 9.1epss 0.00

    CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that compromises a user's credentials can gain access to the victim's…

  • CVE-2025-47790MedMay 16, 2025
    risk 0.00cvss 6.4epss 0.00

    Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have a bug with session handling. The bug caused skipping the…

  • CVE-2025-31478HigApr 16, 2025
    risk 0.00cvss 8.2epss 0.00

    Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restrictions on email address domains or…

  • CVE-2025-25205HigFeb 12, 2025
    risk 0.00cvss 8.2epss 0.04

    Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Attackers can craft URLs…

  • CVE-2024-52518MedNov 15, 2024
    risk 0.00cvss 4.4epss 0.01

    Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is recommended that the Nextcloud…

  • CVE-2024-47768HigOct 4, 2024
    risk 0.00cvss 8.1epss 0.01

    Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery system where there does not appear to be a check to make sure the user has been sent the recovery email and entered the correct…

  • CVE-2024-47070CriSep 27, 2024
    risk 0.00cvss 9.0epss 0.01

    authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibility of logging into any…

  • CVE-2024-47218CriSep 22, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.

  • CVE-2024-37313HigJun 14, 2024
    risk 0.00cvss 7.3epss 0.00

    Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and…

  • CVE-2024-2873CriMar 25, 2024
    risk 0.00cvss 9.1epss 0.01

    A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.

  • CVE-2023-52161HigFeb 22, 2024
    risk 0.00cvss 7.5epss 0.01

    The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with…

  • CVE-2024-25618MedFeb 14, 2024
    risk 0.00cvss 4.2epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to existing local users with the same e-mail address. This results in a possible account takeover if…

  • CVE-2024-0822HigJan 25, 2024
    risk 0.00cvss 7.5epss 0.01

    An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.

  • CVE-2024-0879MedJan 25, 2024
    risk 0.00cvss 6.5epss 0.00

    Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.

  • CVE-2024-21654MedJan 12, 2024
    risk 0.00cvss 4.8epss 0.00

    Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA…

  • CVE-2024-21638CriJan 10, 2024
    risk 0.00cvss 9.1epss 0.02

    Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azure environments as the Service Principal…

  • CVE-2023-49791MedDec 22, 2023
    risk 0.00cvss 5.4epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when an attacker manages…

  • CVE-2023-49790MedDec 22, 2023
    risk 0.00cvss 4.3epss 0.00

    The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform. Prior to version 4.9.2, the application can be used without providing the 4 digit PIN code. Nextcloud iOS Files app should be upgraded to 4.9.2 to receive the patch.…