VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 56 of 241
  • CVE-2025-32879HigJun 20, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attacker to connect with the device via BLE if no other device is connected. While connected, none of the BLE services and…

  • CVE-2024-57190CriJun 10, 2025
    risk 0.57cvss 9.8epss 0.01

    Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.

  • CVE-2025-4144CriMay 1, 2025
    risk 0.57cvss 9.8epss 0.01

    PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: …

  • CVE-2025-1475CriMar 7, 2025
    risk 0.57cvss 9.8epss 0.01

    The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated attackers to log in as any…

  • CVE-2025-26326HigFeb 28, 2025
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which allows an attacker to obtain total control of the remote system by guessing a weak password. The problem occurs because these add-ons accept…

  • CVE-2024-57046HigFeb 18, 2025
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.

  • CVE-2024-46434HigFeb 10, 2025
    risk 0.57cvss 8.8epss 0.01

    Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP request.

  • CVE-2024-12919CriJan 14, 2025
    risk 0.57cvss 9.8epss 0.01

    The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_payment_redirect_link function using the…

  • CVE-2024-1609HigDec 25, 2024
    risk 0.57cvss epss 0.00

    In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.

  • CVE-2024-0130HigDec 6, 2024
    risk 0.57cvss 8.8epss 0.00

    NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request through the Ethernet management interface. A successful exploit of this vulnerability might lead to…

  • CVE-2024-47533CriNov 18, 2024
    risk 0.57cvss 9.8epss 0.04

    Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows…

  • CVE-2023-29117HigNov 5, 2024
    risk 0.57cvss 8.8epss 0.00

    Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.

  • CVE-2023-22650HigOct 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication provider (AP). This characteristic also applies to disabled or revoked users, Rancher will not reflect these modifications which…

  • CVE-2024-38139HigOct 15, 2024
    risk 0.57cvss 8.7epss 0.01

    Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-45148HigOct 10, 2024
    risk 0.57cvss 8.8epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to gain unauthorized access without…

  • CVE-2024-41589HigOct 3, 2024
    risk 0.57cvss 8.8epss 0.00

    DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.

  • CVE-2024-41929HigSep 18, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.

  • CVE-2024-38225HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

  • CVE-2024-45346HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.00

    The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security…

  • CVE-2024-42038HigAug 8, 2024
    risk 0.57cvss 8.8epss 0.00

    Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.