HYPR kayıtları
hypr üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %73,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-287 Improper Authentication1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-306 Missing Authentication for Critical Function1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-0834İstismar yok | Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issuehypr · workforce access · CWE-732 | Kritik9,8 | — | %0,4 | 28 Nis 2023 |
35İzleyin | CVE-2022-2193İstismar yok | Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authypr · hypr server · CWE-280 | Yüksek8,8 | — | %0,9 | 19 Tem 2022 |
35İzleyin | CVE-2022-2192İstismar yok | Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate hypr · hypr server · CWE-425 | Yüksek8,8 | — | %0,9 | 19 Tem 2022 |
35İzleyin | CVE-2023-1477İstismar yok | Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak hypr · keycloak authenticator · CWE-287 | Yüksek8,8 | — | %0,6 | 28 Nis 2023 |
35İzleyin | CVE-2023-1837İstismar yok | Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affhypr · hypr server · CWE-306 | Yüksek8,8 | — | %0,5 | 23 May 2023 |
35İzleyin | CVE-2022-3258İstismar yok | Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.hypr · workforce access · CWE-732 | Yüksek8,8 | — | %0,3 | 3 Kas 2022 |
31İzleyin | CVE-2022-1984İstismar yok | This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before versihypr · workforce access · CWE-502 | Yüksek7,8 | — | %0,2 | 19 Tem 2022 |
31İzleyin | CVE-2023-6336İstismar yok | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filenahypr · workforce access · CWE-59 | Yüksek7,8 | — | %0,2 | 16 Oca 2024 |
31İzleyin | CVE-2023-6335İstismar yok | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filehypr · workforce access · CWE-59 | Yüksek7,8 | — | %0,2 | 16 Oca 2024 |
31İzleyin | CVE-2023-6334İstismar yok | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buhypr · workforce access · CWE-120 | Yüksek7,8 | — | %0,1 | 16 Oca 2024 |
28İzleyin | CVE-2024-8273İstismar yok | Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.hypr · hypr server · CWE-290 | Yüksek7,1 | — | %0,3 | 11 Ara 2025 |
28İzleyin | CVE-2024-0068İstismar yok | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.Thishypr · workforce access · CWE-59 | Yüksek7,1 | — | %0,2 | 29 Şub 2024 |
22İzleyin | CVE-2026-2414İstismar yok | Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.hypr · hypr · CWE-639 | Orta5,6 | — | %0,3 | 25 Mar 2026 |
22İzleyin | CVE-2023-5097İstismar yok | Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: beforhypr · workforce access · CWE-22 | Orta5,5 | — | %0,2 | 16 Oca 2024 |
22İzleyin | CVE-2024-1721İstismar yok | Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue ahypr · passwordless · CWE-347 | Orta5,6 | — | %0,1 | 21 May 2024 |
- CVE-2023-083439İzleyin
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue
KritikCVSS 9,8İstismar yokEPSS %0hypr · workforce access28 Nis 2023
- CVE-2022-219335İzleyin
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 aut
YüksekCVSS 8,8İstismar yokEPSS %1hypr · hypr server19 Tem 2022
- CVE-2022-219235İzleyin
Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate
YüksekCVSS 8,8İstismar yokEPSS %1hypr · hypr server19 Tem 2022
- CVE-2023-147735İzleyin
Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak
YüksekCVSS 8,8İstismar yokEPSS %1hypr · keycloak authenticator28 Nis 2023
- CVE-2023-183735İzleyin
Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue aff
YüksekCVSS 8,8İstismar yokEPSS %1hypr · hypr server23 May 2023
- CVE-2022-325835İzleyin
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.
YüksekCVSS 8,8İstismar yokEPSS %0hypr · workforce access3 Kas 2022
- CVE-2022-198431İzleyin
This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before versi
YüksekCVSS 7,8İstismar yokEPSS %0hypr · workforce access19 Tem 2022
- CVE-2023-633631İzleyin
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filena
YüksekCVSS 7,8İstismar yokEPSS %0hypr · workforce access16 Oca 2024
- CVE-2023-633531İzleyin
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled File
YüksekCVSS 7,8İstismar yokEPSS %0hypr · workforce access16 Oca 2024
- CVE-2023-633431İzleyin
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Bu
YüksekCVSS 7,8İstismar yokEPSS %0hypr · workforce access16 Oca 2024
- CVE-2024-827328İzleyin
Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.
YüksekCVSS 7,1İstismar yokEPSS %0hypr · hypr server11 Ara 2025
- CVE-2024-006828İzleyin
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This
YüksekCVSS 7,1İstismar yokEPSS %0hypr · workforce access29 Şub 2024
- CVE-2026-241422İzleyin
Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.
OrtaCVSS 5,6İstismar yokEPSS %0hypr · hypr25 Mar 2026
- CVE-2023-509722İzleyin
Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: befor
OrtaCVSS 5,5İstismar yokEPSS %0hypr · workforce access16 Oca 2024
- CVE-2024-172122İzleyin
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue a
OrtaCVSS 5,6İstismar yokEPSS %0hypr · passwordless21 May 2024