VYPR

CWE-287

Improper Authentication

ClassDraftLikelihood: High

Description

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94

CVEs mapped to this weakness (4,804)

page 73 of 241
  • CVE-2024-50641HigAug 21, 2025
    risk 0.53cvss 8.1epss 0.00

    An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnerability to access API without any token.

  • CVE-2025-53786HigAug 6, 2025
    risk 0.53cvss 8.0epss 0.07

    On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation,…

  • CVE-2025-6505HigJul 29, 2025
    risk 0.53cvss 8.1epss 0.00

    Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and…

  • CVE-2025-54369CriJul 24, 2025
    risk 0.53cvss epss 0.01

    Node-SAML is a SAML library not dependent on any frameworks that runs in Node. In versions 5.0.1 and below, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. This allows an…

  • CVE-2025-53771MedJul 20, 2025
    risk 0.53cvss 6.5epss 1.00

    Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-6763HigJun 27, 2025
    risk 0.53cvss 8.1epss 0.01

    A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60. Affected by this issue is some unknown functionality of the file /setupA.cfg of the component Web-based Management Interface. Performing manipulation results…

  • CVE-2025-22236HigJun 13, 2025
    risk 0.53cvss 8.1epss 0.00

    Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).

  • CVE-2025-46572CriMay 6, 2025
    risk 0.53cvss epss 0.00

    passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication by crafting a SAMLResponse. This can be…

  • CVE-2024-11917HigApr 25, 2025
    risk 0.53cvss 8.1epss 0.00

    The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This…

  • CVE-2025-27086HigApr 21, 2025
    risk 0.53cvss 8.1epss 0.00

    A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.

  • CVE-2024-8053HigMar 20, 2025
    risk 0.53cvss 8.2epss 0.01

    In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload,…

  • CVE-2024-11087HigMar 8, 2025
    risk 0.53cvss 8.1epss 0.00

    The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned by the social…

  • CVE-2025-1723HigMar 3, 2025
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.

  • CVE-2025-24032CriFeb 10, 2025
    risk 0.53cvss epss 0.01

    PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy is set to none (the default value), then pam_pkcs11 will only check if the user is capable of logging into the token. An attacker may create a…

  • CVE-2023-31279HigDec 21, 2024
    risk 0.53cvss 8.1epss 0.00

    The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the owner has not disabled the AirVantage Management Service on the devices or registered the device. This could enable an attacker to…

  • CVE-2024-10111HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for…

  • CVE-2024-45404HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can break through the two-factor authentication…

  • CVE-2024-11293HigDec 4, 2024
    risk 0.53cvss 8.1epss 0.01

    The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.9. This is due…

  • CVE-2024-53990CriDec 2, 2024
    risk 0.53cvss epss 0.01

    The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any HTTP request, the automatically enabled and self-managed CookieStore (aka cookie jar) will silently replace explicitly defined…

  • CVE-2024-45369HigNov 22, 2024
    risk 0.53cvss 8.1epss 0.01

    The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.