← Back
CWE-287

4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zoom
4Meetings
RoomsVirtual Desktop Infrastructure+1 more
Jun 17, 2026
Nov 15, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.
1Typo3
1Typo3
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two different sites. Eg. first.example.org and second.example.com. In affected...Show more
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two different sites. Eg. first.example.org and second.example.com. In affected versions a session cookie generated for the first site can be reused on the second site without requiring additional authentication. This vulnerability has been addressed in versions 8.7.55, 9.5.44, 10.4.41, 11.5.33, and 12.4.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Intel
1Realtek Sd Card Reader Driver
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version 10.0.19041.29098 may allow an authenticated user to potentially enable escalatio...Show more
Improper authentication in some Intel(R) NUC Kits NUC7PJYH and NUC7CJYH Realtek* SD Card Reader Driver installation software before version 10.0.19041.29098 may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Intel
1Usb Firmware
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Unison Software
Jun 17, 2026
Nov 14, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.
1Pfsense
1Pfsense
Jun 17, 2026
Nov 9, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
1Apereo
1Central Authentication Service
Jun 17, 2026
Nov 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown wheth...Show more
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.Show less
1Samsung
1Pass
Jun 17, 2026
Nov 7, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.
1Samsung
1Android
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.
1Qualcomm
265315 5g Iot Modem Firmware
9205 Lte Modem FirmwareAqt1000 Firmware+262 more
Jun 17, 2026
Nov 7, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory Corruption in Core due to secure memory access by user while loading modem image.
1Strapi
1Strapi
Jun 17, 2026
Nov 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modif...Show more
strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in version 4.13.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
2Opensc Project
Redhat
2Enterprise Linux
Opensc
Jun 17, 2026
Nov 6, 2023
N/A· v4
6.6 MEDIUM· v3
N/A· v2
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed...Show more
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small, permanently connected tokens to computers. Additionally, the token can internally track login status. This flaw allows an attacker to gain unauthorized access, carry out malicious actions, or compromise the system without the user's awareness.Show less
1Kaoshifeng
1Yunfan Learning Examination System
Jun 17, 2026
Nov 4, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function.
1Ivanti
1Automation
Jun 17, 2026
Nov 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Nov 2, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restric...Show more
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse the RMI service to modify calendar items using RMI. RMI access is restricted to localhost by default. The interface has been updated to require authenticated requests. No publicly available exploits are known. Show less
2Fujifilm
Xerox
93Apeos 2560 Firmware
Apeos 2560 Gk FirmwareApeos 3060 Firmware+90 more
Jun 17, 2026
Nov 2, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength...Show more
Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the information such as the server credentials may be obtained from the exported Address Book data. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].Show less
1Moxa
27Nport 6150 T Firmware
Nport 6150 FirmwareNport 6250 M Sc T Firmware+24 more
Jun 17, 2026
Nov 1, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allow...Show more
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web service. Show less
1Goauthentik
1Authentik
Jun 17, 2026
Oct 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin u...Show more
authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint to create the default admin user, which can also optionally set the default admin users' password from an environment variable. When the user is deleted, the `initial-setup` flow used to configure authentik after the first installation becomes available again. authentik 2023.8.4 and 2023.10.2 fix this issue. As a workaround, ensure the default admin user (Username `akadmin`) exists and has a password set. It is recommended to use a very strong password for this user, and store it in a secure location like a password manager. It is also possible to deactivate the user to prevent any logins as akadmin.Show less
1Fit2cloud
1Cloudexplorer Lite
Jun 17, 2026
Oct 30, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a p...Show more
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this issue.Show less
1Google
1Android
Jun 17, 2026
Oct 30, 2023
N/A· v4
5.0 MEDIUM· v3
N/A· v2
In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional e...Show more
In Bluetooth, there is a possible way for a paired Bluetooth device to access a long term identifier for an Android device due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Show less