← Back
CWE-287

4,477 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,477)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
13par Service Processor Firmware
Jun 17, 2026
Jul 16, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The vulnerability could be remotely exploited to bypass authentication.
1Mattermost
1Mattermost Mobile
Jun 17, 2026
Jul 15, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another serve...Show more
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.Show less
-
-
Jun 17, 2026
Jul 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web interface and the user portal. Affected versi...Show more
The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web interface and the user portal. Affected versions include UTM 11.5 through 12.6.4 and Reseller Preview 12.7.0. The issue has been fixed in UTM 12.6.5 and 12.7.1.Show less
1Nuvoton
4Npcm705r Firmware
Npcm710r FirmwareNpcm730r Firmware+1 more
Jun 17, 2026
Jul 11, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header...Show more
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.Show less
1Instawp
1Instawp Connect
Jun 17, 2026
Jul 11, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. Th...Show more
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username, and to perform a variety of other administrative tasks. NOTE: This vulnerability was partially fixed in 0.1.0.44, but was still exploitable via Cross-Site Request Forgery.Show less
1Citrix
1Netscaler Console
Jun 17, 2026
Jul 10, 2024
9.4 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
Sensitive information disclosure in NetScaler Console
1Microsoft
6Windows Server 2008
Windows Server 2012Windows Server 2016+3 more
Jun 17, 2026
Jul 9, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
1Ibm
1Storage Virtualize
Jun 17, 2026
Jul 8, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data. IBM X-Force ID: 29...Show more
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data. IBM X-Force ID: 295935.Show less
1Mattermost
1Mattermost
Jun 17, 2026
Jul 3, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve...Show more
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster token via a timing attack during remote cluster token comparison.Show less
-
-
Jun 17, 2026
Jul 2, 2024
8.6 HIGH· v4
N/A· v3
N/A· v2
In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.
1Samsung
1Smartthings
Jun 17, 2026
Jul 2, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.
1Samsung
1Android
Jun 17, 2026
Jul 2, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
1Samsung
1Android
Jun 17, 2026
Jul 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.
1Samsung
1Android
Jun 17, 2026
Jul 2, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.
1N Able
1N Central
Jun 17, 2026
Jul 1, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-c...Show more
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.Show less
-
-
Jun 17, 2026
Jun 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authentication flow has multiple issues that weakens its one-time nature. Specifically, the lack of 2FA for...Show more
Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authentication flow has multiple issues that weakens its one-time nature. Specifically, the lack of 2FA for changing security settings allows attacker with CSRF or XSS primitives to change such settings without user interaction and credentials are required. This vulnerability has been patched in version 0.10. Show less
-
-
Jun 17, 2026
Jun 26, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.
1Apple
5Airpods Firmware
Airpods Max FirmwareAirpods Pro Firmware+2 more
Jun 17, 2026
Jun 26, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a c...Show more
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.Show less
1Progress
1Whatsup Gold
Jun 17, 2026
Jun 25, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability allows unauthenticated attackers to disclose Windows Credentials stored...Show more
In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability allows unauthenticated attackers to disclose Windows Credentials stored in the product Credential Library.Show less
1Progress
1Moveit Transfer
Jun 17, 2026
Jun 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 20...Show more
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.Show less