HYPR records
15 published records for vendor hypr.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 73.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-287 Improper Authentication1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-306 Missing Authentication for Critical Function1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-0834No exploit | Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issuehypr · workforce access · CWE-732 | Critical9.8 | — | 0.4% | Apr 28, 2023 |
35Monitor | CVE-2022-2193No exploit | Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authypr · hypr server · CWE-280 | High8.8 | — | 0.9% | Jul 19, 2022 |
35Monitor | CVE-2022-2192No exploit | Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate hypr · hypr server · CWE-425 | High8.8 | — | 0.9% | Jul 19, 2022 |
35Monitor | CVE-2023-1477No exploit | Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak hypr · keycloak authenticator · CWE-287 | High8.8 | — | 0.6% | Apr 28, 2023 |
35Monitor | CVE-2023-1837No exploit | Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affhypr · hypr server · CWE-306 | High8.8 | — | 0.5% | May 23, 2023 |
35Monitor | CVE-2022-3258No exploit | Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.hypr · workforce access · CWE-732 | High8.8 | — | 0.3% | Nov 3, 2022 |
31Monitor | CVE-2022-1984No exploit | This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before versihypr · workforce access · CWE-502 | High7.8 | — | 0.2% | Jul 19, 2022 |
31Monitor | CVE-2023-6336No exploit | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filenahypr · workforce access · CWE-59 | High7.8 | — | 0.2% | Jan 16, 2024 |
31Monitor | CVE-2023-6335No exploit | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filehypr · workforce access · CWE-59 | High7.8 | — | 0.2% | Jan 16, 2024 |
31Monitor | CVE-2023-6334No exploit | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buhypr · workforce access · CWE-120 | High7.8 | — | 0.1% | Jan 16, 2024 |
28Monitor | CVE-2024-8273No exploit | Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.hypr · hypr server · CWE-290 | High7.1 | — | 0.3% | Dec 11, 2025 |
28Monitor | CVE-2024-0068No exploit | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.Thishypr · workforce access · CWE-59 | High7.1 | — | 0.2% | Feb 29, 2024 |
22Monitor | CVE-2026-2414No exploit | Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.hypr · hypr · CWE-639 | Medium5.6 | — | 0.3% | Mar 25, 2026 |
22Monitor | CVE-2023-5097No exploit | Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: beforhypr · workforce access · CWE-22 | Medium5.5 | — | 0.2% | Jan 16, 2024 |
22Monitor | CVE-2024-1721No exploit | Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue ahypr · passwordless · CWE-347 | Medium5.6 | — | 0.1% | May 21, 2024 |
- CVE-2023-083439Monitor
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue
CriticalCVSS 9.8No exploitEPSS 0%hypr · workforce accessApr 28, 2023
- CVE-2022-219335Monitor
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 aut
HighCVSS 8.8No exploitEPSS 1%hypr · hypr serverJul 19, 2022
- CVE-2022-219235Monitor
Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate
HighCVSS 8.8No exploitEPSS 1%hypr · hypr serverJul 19, 2022
- CVE-2023-147735Monitor
Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak
HighCVSS 8.8No exploitEPSS 1%hypr · keycloak authenticatorApr 28, 2023
- CVE-2023-183735Monitor
Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue aff
HighCVSS 8.8No exploitEPSS 1%hypr · hypr serverMay 23, 2023
- CVE-2022-325835Monitor
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.
HighCVSS 8.8No exploitEPSS 0%hypr · workforce accessNov 3, 2022
- CVE-2022-198431Monitor
This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before versi
HighCVSS 7.8No exploitEPSS 0%hypr · workforce accessJul 19, 2022
- CVE-2023-633631Monitor
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filena
HighCVSS 7.8No exploitEPSS 0%hypr · workforce accessJan 16, 2024
- CVE-2023-633531Monitor
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled File
HighCVSS 7.8No exploitEPSS 0%hypr · workforce accessJan 16, 2024
- CVE-2023-633431Monitor
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Bu
HighCVSS 7.8No exploitEPSS 0%hypr · workforce accessJan 16, 2024
- CVE-2024-827328Monitor
Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.
HighCVSS 7.1No exploitEPSS 0%hypr · hypr serverDec 11, 2025
- CVE-2024-006828Monitor
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This
HighCVSS 7.1No exploitEPSS 0%hypr · workforce accessFeb 29, 2024
- CVE-2026-241422Monitor
Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.
MediumCVSS 5.6No exploitEPSS 0%hypr · hyprMar 25, 2026
- CVE-2023-509722Monitor
Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: befor
MediumCVSS 5.5No exploitEPSS 0%hypr · workforce accessJan 16, 2024
- CVE-2024-172122Monitor
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue a
MediumCVSS 5.6No exploitEPSS 0%hypr · passwordlessMay 21, 2024