CWE-287
4,497 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,497)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 6Nexus 93180yc Fx3 Firmware Nexus 93180yc Fx3s FirmwareUcs 64108 Firmware+3 moreJun 17, 2026 Feb 23, 2023 N/A· v4 4.6 MEDIUM· v3 N/A· v2 A vulnerability in the CLI console login authentication of Cisco Nexus 9300-FX3 Series Fabric Extender (FEX) when used in UCS Fabric Interconnect deployments could allow an unauthenticated attacker with physical access t...Show more |
An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password. |
A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation le...Show more |
1Employee Task Management System Project 1Employee Task Management System Jun 17, 2026 Feb 18, 2023 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper a...Show more |
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privilege via network access. |
Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access. |
Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass. |
1Solarwinds 1Server And Application Monitor Jun 17, 2026 Feb 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos. |
1Microsoft 13Windows 10 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Feb 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows Kerberos Elevation of Privilege Vulnerability |
Microsoft OneNote Elevation of Privilege Vulnerability |
Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using thi...Show more |
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata service (GMS) will use the X-DataHub-Actor HTTP header to infer the us...Show more |
Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast. |
Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information. |
An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition. |
The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiality. |
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster mana...Show more |
1Atlassian 1Jira Service Management Jun 17, 2026 Feb 1, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain ci...Show more |
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. |