CWE-287
4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,492)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Openautomationsoftware 1Oas Platform Jun 17, 2026 Sep 5, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An...Show more |
A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures, potentially leading to the disclosure of...Show more |
Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) before build 32047. |
1Zohocorp 17Manageengine Ad360 Manageengine Adaudit PlusManageengine Admanager Plus+14 moreJun 17, 2026 Aug 28, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data...Show more |
Walchem Intuition 9 firmware versions prior to v4.21 are vulnerable to improper authentication. Login credentials are stored in a format that could allow an attacker to use them as-is to login and gain access to the devi...Show more |
Improper authentication vulnerability in Rakuten WiFi Pocket all versions allows a network-adjacent attacker to log in to the product's Management Screen. As a result, sensitive information may be obtained and/or the set...Show more |
1Cbc 23Dr 16f42a Firmware Dr 16f45at FirmwareDr 16h Firmware+20 moreJun 17, 2026 Aug 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the deta...Show more |
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information. |
1Devolutions 1Remote Desktop Manager Jun 17, 2026 Aug 21, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution right...Show more |
1Ruijienetworks 1Rg Ew1200g Firmware Jun 17, 2026 Aug 18, 2023 N/A· v4 8.8 HIGH· v3 7.5 HIGH· v2 A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authenticat...Show more |
Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthen...Show more |
TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate authentication measures implemented in the web API handler, allowing low-pr...Show more |
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token. |
1Dell 111Alienware M15 R7 Firmware Alienware M16 FirmwareAlienware M18 Firmware+108 moreJun 17, 2026 Aug 16, 2023 N/A· v4 3.9 LOW· v3 N/A· v2 Dell BIOS contains an improper authentication vulnerability. A malicious user with physical access to the system may potentially exploit this vulnerability in order to modify a security-critical UEFI variable without kn...Show more |
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is uni...Show more |
PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) o...Show more |
1Dataprobe 22Iboot Pdu4 C20 Firmware Iboot Pdu4 N20 FirmwareIboot Pdu4a C10 Firmware+19 moreJun 17, 2026 Aug 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitati...Show more |
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally. |
EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first factor is sufficient to change an account's...Show more |
Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Authentication Abuse.This issue affects Genian NAC V4.0: from V4.0.0 th...Show more |