CWE-287
4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,492)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zoom 4Meetings RoomsVirtual Desktop Infrastructure+1 moreJun 17, 2026 Nov 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. |
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two different sites. Eg. first.example.org and second.example.com. In affected...Show more |
1Intel 1Realtek Sd Card Reader Driver Jun 17, 2026 Nov 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version 10.0.19041.29098 may allow an authenticated user to potentially enable escalatio...Show more |
Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access. |
Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. |
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification. |
1Apereo 1Central Authentication Service Jun 17, 2026 Nov 9, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown wheth...Show more |
Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication. |
Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background. |
1Qualcomm 265315 5g Iot Modem Firmware 9205 Lte Modem FirmwareAqt1000 Firmware+262 moreJun 17, 2026 Nov 7, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Memory Corruption in Core due to secure memory access by user while loading modem image. |
strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modif...Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 17, 2026 Nov 6, 2023 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed...Show more |
1Kaoshifeng 1Yunfan Learning Examination System Jun 17, 2026 Nov 4, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function. |
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication. |
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restric...Show more |
2Fujifilm Xerox93Apeos 2560 Firmware Apeos 2560 Gk FirmwareApeos 3060 Firmware+90 moreJun 17, 2026 Nov 2, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength...Show more |
1Moxa 27Nport 6150 T Firmware Nport 6150 FirmwareNport 6250 M Sc T Firmware+24 moreJun 17, 2026 Nov 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allow...Show more |
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin u...Show more |
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a p...Show more |
In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional e...Show more |