Записи HYPR
15 опубликованных записей вендора hypr.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 73,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-280 Improper Handling of Insufficient Permissions or Privileges1
- CWE-287 Improper Authentication1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-306 Missing Authentication for Critical Function1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-0834Эксплойта нет | Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issuehypr · workforce access · CWE-732 | Критическая9,8 | — | 0,4 % | 28 апр. 2023 г. |
35Наблюдать | CVE-2022-2193Эксплойта нет | Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authypr · hypr server · CWE-280 | Высокая8,8 | — | 0,9 % | 19 июл. 2022 г. |
35Наблюдать | CVE-2022-2192Эксплойта нет | Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate hypr · hypr server · CWE-425 | Высокая8,8 | — | 0,9 % | 19 июл. 2022 г. |
35Наблюдать | CVE-2023-1477Эксплойта нет | Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak hypr · keycloak authenticator · CWE-287 | Высокая8,8 | — | 0,6 % | 28 апр. 2023 г. |
35Наблюдать | CVE-2023-1837Эксплойта нет | Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affhypr · hypr server · CWE-306 | Высокая8,8 | — | 0,5 % | 23 мая 2023 г. |
35Наблюдать | CVE-2022-3258Эксплойта нет | Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.hypr · workforce access · CWE-732 | Высокая8,8 | — | 0,3 % | 3 нояб. 2022 г. |
31Наблюдать | CVE-2022-1984Эксплойта нет | This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before versihypr · workforce access · CWE-502 | Высокая7,8 | — | 0,2 % | 19 июл. 2022 г. |
31Наблюдать | CVE-2023-6336Эксплойта нет | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filenahypr · workforce access · CWE-59 | Высокая7,8 | — | 0,2 % | 16 янв. 2024 г. |
31Наблюдать | CVE-2023-6335Эксплойта нет | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filehypr · workforce access · CWE-59 | Высокая7,8 | — | 0,2 % | 16 янв. 2024 г. |
31Наблюдать | CVE-2023-6334Эксплойта нет | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Buhypr · workforce access · CWE-120 | Высокая7,8 | — | 0,1 % | 16 янв. 2024 г. |
28Наблюдать | CVE-2024-8273Эксплойта нет | Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.hypr · hypr server · CWE-290 | Высокая7,1 | — | 0,3 % | 11 дек. 2025 г. |
28Наблюдать | CVE-2024-0068Эксплойта нет | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.Thishypr · workforce access · CWE-59 | Высокая7,1 | — | 0,2 % | 29 февр. 2024 г. |
22Наблюдать | CVE-2026-2414Эксплойта нет | Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.hypr · hypr · CWE-639 | Средняя5,6 | — | 0,3 % | 25 мар. 2026 г. |
22Наблюдать | CVE-2023-5097Эксплойта нет | Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: beforhypr · workforce access · CWE-22 | Средняя5,5 | — | 0,2 % | 16 янв. 2024 г. |
22Наблюдать | CVE-2024-1721Эксплойта нет | Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue ahypr · passwordless · CWE-347 | Средняя5,6 | — | 0,1 % | 21 мая 2024 г. |
- CVE-2023-083439Наблюдать
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hypr · workforce access28 апр. 2023 г.
- CVE-2022-219335Наблюдать
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 aut
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hypr · hypr server19 июл. 2022 г.
- CVE-2022-219235Наблюдать
Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hypr · hypr server19 июл. 2022 г.
- CVE-2023-147735Наблюдать
Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hypr · keycloak authenticator28 апр. 2023 г.
- CVE-2023-183735Наблюдать
Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue aff
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hypr · hypr server23 мая 2023 г.
- CVE-2022-325835Наблюдать
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %hypr · workforce access3 нояб. 2022 г.
- CVE-2022-198431Наблюдать
This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability in HYPR Workforce Access (WFA) before versi
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %hypr · workforce access19 июл. 2022 г.
- CVE-2023-633631Наблюдать
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filena
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %hypr · workforce access16 янв. 2024 г.
- CVE-2023-633531Наблюдать
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled File
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %hypr · workforce access16 янв. 2024 г.
- CVE-2023-633431Наблюдать
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in HYPR Workforce Access on Windows allows Overflow Bu
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %hypr · workforce access16 янв. 2024 г.
- CVE-2024-827328Наблюдать
Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %hypr · hypr server11 дек. 2025 г.
- CVE-2024-006828Наблюдать
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %hypr · workforce access29 февр. 2024 г.
- CVE-2026-241422Наблюдать
Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.
СредняяCVSS 5,6Эксплойта нетEPSS 0 %hypr · hypr25 мар. 2026 г.
- CVE-2023-509722Наблюдать
Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: befor
СредняяCVSS 5,5Эксплойта нетEPSS 0 %hypr · workforce access16 янв. 2024 г.
- CVE-2024-172122Наблюдать
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue a
СредняяCVSS 5,6Эксплойта нетEPSS 0 %hypr · passwordless21 мая 2024 г.