← Back
CWE-287

4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yotuwp
1Video Gallery
Jun 17, 2026
Aug 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.
1Redhat
3Keycloak
Openshift Container PlatformSingle Sign On
Jun 17, 2026
Aug 23, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with...Show more
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this vulnerability is to confidentiality and integrity.Show less
1Trendnet
1Tv Ip572pi Firmware
Jul 9, 2026
Aug 23, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.
1Zengenti
1Contensis
Jun 17, 2026
Aug 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.
1Wwbn
1Avideo
Jun 17, 2026
Aug 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' password hash will be able to use it to directly login into the account, lea...Show more
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' password hash will be able to use it to directly login into the account, leading to increased privileges.Show less
1Miniorange
1Wp Oauth Server
Jun 17, 2026
Aug 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
1Intel
1Edge Insights For Industrial
Jun 17, 2026
Aug 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
1Contract Management System Project
1Contract Managment System
Jun 17, 2026
Aug 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
1Softing
6Edgeaggregator
EdgeconnectorOpc+3 more
Jun 17, 2026
Aug 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to p...Show more
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the `admin` password. There is no warning or prompt to ask the user to change the default password, and to change the password, many steps are required.Show less
1Sequi
1Portbloque S Firmware
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process and gain user-level access to the device.
1Aviatrix
1Gateway
Jun 17, 2026
Aug 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.
1Dlink
1Go Rt Ac750 Firmware
Jul 9, 2026
Aug 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
1Yugabyte
1Yugabytedb
Jun 17, 2026
Aug 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authenticatio...Show more
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Aug 12, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads currently allow users...Show more
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads currently allow users with root privileges to switch out the target with an equivalent dm-linear target and bypass verification till reboot. This allows root to bypass LoadPin and can be used to load untrusted and unverified kernel modules and firmware, which implies arbitrary kernel execution and persistence for peripherals that do not verify firmware updates. We recommend upgrading past commit 4caae58406f8ceb741603eee460d79bacca9b1b5Show less
1Jetbrains
1Ktor
Jun 17, 2026
Aug 12, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
1Company Website Cms Project
1Company Website Cms
Jun 17, 2026
Aug 11, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/settings. The manipulation leads to...Show more
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/settings. The manipulation leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206161 was assigned to this vulnerability.Show less
1Megatech
1Msnswitch Firmware
Jun 17, 2026
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within...Show more
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technologies Inc MSNSwitch MNT.2408 allows unauthenticated attackers to arbitrarily configure settings within the application, leading to remote code execution.Show less
1Dell
108Chengming 3980 Firmware
Chengming 3990 FirmwareChengming 3991 Firmware+105 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanism...Show more
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability by bypassing drive security mechanisms in order to gain access to the system.Show less
1Jumpdemand
1Activedemand
Jun 17, 2026
Aug 5, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.
1Google
1Android
Jun 17, 2026
Aug 5, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.