← Back
CWE-287

4,488 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,488)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mintplexlabs
1Vector Admin
Jun 17, 2026
Jan 25, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.
1Hp
1Oneview
Jun 17, 2026
Jan 23, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Jan 23, 2024
N/A· v4
6.2 MEDIUM· v3
N/A· v2
The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly disabled.
1Apple
1Macos
Jun 17, 2026
Jan 23, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching s...Show more
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the previous logged in user’s desktop from the fast user switching screen.Show less
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jan 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.
1Evershop
1Evershop
Jun 17, 2026
Jan 13, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
1Rubygems
1Rubygems.org
Jun 17, 2026
Jan 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotte...Show more
Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form allows an attacker to bypass the MFA requirement and takeover the account. This vulnerability has been patched in commit 0b3272a.Show less
1Clerk
1Javascript
Jun 17, 2026
Jan 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3...Show more
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3. Show less
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Jan 12, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
1Hongdian
1H8951 4g Esp Firmware
Jun 17, 2026
Jan 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.
1Gl Inet
12Gl A1300 Firmware
Gl Ar300m FirmwareGl Ar750 Firmware+9 more
Jun 17, 2026
Jan 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6,...Show more
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.Show less
1Hozard
1Alarm System
Jun 17, 2026
Jan 11, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an attacker to bring the alarm system to a di...Show more
Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an attacker to bring the alarm system to a disarmed state from any given phone number.Show less
1Microsoft
1Azure Ipam
Jun 17, 2026
Jan 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write acces...Show more
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azure environments as the Service Principal used is only assigned the Reader role at the root Management Group level. Until recently, the solution lacked the validation of the passed in authentication token which may result in attacker impersonating any privileged user to access data stored within the IPAM instance and subsequently from Azure, causing an elevation of privilege. This vulnerability has been patched in version 3.0.0. Show less
1Bosch
1Nexo Os
Jun 17, 2026
Jan 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by...Show more
The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users, via crafted HTTP requests, or indirectly by unauthenticated users, by accessing already-exported backup packages, or crafting an import package and inducing an authenticated victim into sending the HTTP upload request.Show less
1Korenix
42Jetnet 4508 W Firmware
Jetnet 4508 FirmwareJetnet 4508f M Firmware+39 more
Jun 17, 2026
Jan 9, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.
1Dataiku
1Data Science Studio
Jun 17, 2026
Jan 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
1Uniwayinfo
5Uw 101x Firmware
Uw 301vpw FirmwareUw 302vp Firmware+2 more
Jun 17, 2026
Jan 7, 2024
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipulation leads to reliance on ip address fo...Show more
A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipulation leads to reliance on ip address for authentication. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-249766 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Onenav
1Onenav
Jun 17, 2026
Jan 7, 2024
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to impr...Show more
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249765 was assigned to this vulnerability.Show less
1Samsung
1Android
Jun 17, 2026
Jan 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
1Recognizeapp
1Omniauth\
Jun 17, 2026
Jan 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/documen...Show more
omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do so, making it susceptible to nOAuth misconfiguration in cases when the `email` is used as a trusted user identifier. This could lead to account takeover. Version 2.0.0 contains a fix for this issue. Show less