CWE-287
4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,504)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut. |
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to byp...Show more |
1Private Cloud Management Platform Project 1Private Cloud Management Platform Jun 17, 2026 Aug 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Han...Show more |
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter. |
A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request. |
BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brute-force attacks. This issue has been patched in version 0.4.5. Admins w...Show more |
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another c...Show more |
1Mb.miniaudioplayer Project 1Mb.miniaudioplayer Nov 21, 2024 Jul 28, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplie...Show more |
3Clusterlabs DebianFedoraproject3Booth Debian LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from...Show more |
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engine...Show more |
1Zohocorp 1Manageengine Supportcenter Plus Jun 17, 2026 Jul 26, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.) |
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml. |
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress. |
Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including privileged users such as the other of the instance. The problem has been...Show more |
1Yikesinc 1Custom Product Tabs For Woocommerce Jun 17, 2026 Jul 21, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update. |
1Atlassian 11Bamboo BitbucketConfluence Data Center+8 moreJun 17, 2026 Jul 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the...Show more |
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication. |
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files. |
Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password. |
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and pass...Show more |