HYPR Corp
First CVE: Jul 19, 2022Active for: 4 years
19
CVEs Published
More CVEs Published than 38% of tracked CNAs
3.8
Avg CVEs / Year
More Avg CVEs / Year than 27% of tracked CNAs
7.7
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by HYPR Corp as a CNA, 73.7% affect products that HYPR Corp develops as a vendor.
73.7%
26.3%
Self-reported: 14Third-party: 5
Of all the CVEs published that affect products developed by HYPR Corp, 100.0% are self-published by HYPR Corp as a CNA.
100.0%
Self-published: 14Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by HYPR Corp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2022
4 years ago
Most Recent CVE
Jun 25, 2026
29 days ago
Top CVEs
All CVEs published by HYPR Corp as a CNA, regardless of affected vendor or product.
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2414CRITICAL Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.5.2 before 10.7.2. | Mar 25, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-4522MEDIUM Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception.
This issue affects HYPR Passwordless: before 11.1.1. | Jun 25, 2026 | 6.7 | 28 | NO | NO |
CVE-2022-3258HIGH Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse. | Nov 3, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-8273HIGH Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1. | Dec 11, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-0834CRITICAL Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issue affects Workforce Access: from 6.12 bef | Apr 28, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-1837HIGH Missing Authentication for critical function vulnerability in HYPR Server allows Authentication Bypass when using Legacy APIs.This issue affects HYPR Server: before 8.0 (with enabl | May 23, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-1477HIGH Improper Authentication vulnerability in HYPR Keycloak Authenticator Extension allows Authentication Abuse.This issue affects HYPR Keycloak Authenticator Extension: before 7.10.2, | Apr 28, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-2193HIGH Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attackers to add a FIDO2 authenticator to arbitrary accounts via par | Jul 19, 2022 | 8.8 | 24 | NO | NO |
CVE-2023-6336HIGH Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: | Jan 16, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-6335HIGH Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This issue affects Workforce Access | Jan 16, 2024 | 7.8 | 22 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA19 CVEs
32%
58%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local10 (52.6%)
Network8 (42.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low15 (78.9%)
High4 (21.1%)
Unknown0 (0.0%)
User Interaction
None13 (68.4%)
Unknown0 (0.0%)
Required1 (5.3%)
Privileges Required
Low13 (68.4%)
High2 (10.5%)
None4 (21.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by HYPR Corp as a CNA.
Media Mentions
Media articles that mention a CVE ID published by HYPR Corp as a CNA — matched by CVE ID, not by organization name.