CWE-287
4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,502)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login...Show more |
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication. |
1Bd 7Bodyguard 121 Twins Firmware Bodyguard 323 Colorvision FirmwareBodyguard 999 603 Firmware+4 moreJun 17, 2026 Dec 5, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or di...Show more |
1Veeam 1Veeam Backup For Google Cloud Jun 17, 2026 Dec 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms. |
MegaRAC Default Credentials Vulnerability |
MegaRAC Default Credentials Vulnerability |
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of the user who posted a blog using the WordPress Post by Email Feature. The...Show more |
1Veritas 2Access Appliance Netbackup Flex Scale ApplianceJun 17, 2026 Dec 4, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges. |
authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized user creation and potential account takeover. With the default flows, unauthenticated users can crea...Show more |
1Ibm 1Websphere Automation For Ibm Cloud Pak For Watson Aiops Jun 17, 2026 Dec 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A local attacker can create an outbound network connection to another system. IBM X-Force ID: 240827.
|
SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges. |
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poison...Show more |
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server. |
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There ar...Show more |
1Epson 9Tm C3500 Firmware Tm C3510 FirmwareTm C3520 Firmware+6 moreJun 17, 2026 Nov 25, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass. |
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL i...Show more |
A vulnerability in NetBatch-Plus software allows unauthorized access to the application.
HPE has provided a workaround and fix. Please refer to HPE Security Bulletin
HPESBNS04388
for details.
|
A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabl...Show more |
1Cisco 2Firepower Services Software For Asa Secure Firewall Management CenterJun 17, 2026 Nov 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and...Show more |
1Qualcomm 69Ar9380 Firmware Csr8811 FirmwareIpq4018 Firmware+66 moreJun 17, 2026 Nov 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Information disclosure in kernel due to improper handling of ICMP requests in Snapdragon Wired Infrastructure and Networking |