← Back
CWE-287

4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Aug 5, 2022
N/A· v4
2.4 LOW· v3
N/A· v2
Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.
1Gitlab
1Gitlab
Jun 17, 2026
Aug 5, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to byp...Show more
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for group members to bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.Show less
1Private Cloud Management Platform Project
1Private Cloud Management Platform
Jun 17, 2026
Aug 5, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Han...Show more
A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown function of the file /management/api/rcx_management/global_config_query of the component POST Request Handler. The manipulation leads to improper authentication. It is possible to launch the attack remotely. VDB-205614 is the identifier assigned to this vulnerability.Show less
1Raneto Project
1Raneto
Jun 17, 2026
Aug 4, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.
1Fortinet
1Fortiadc
Jun 17, 2026
Aug 3, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request.
1Joinbookwyrm
1Bookwyrm
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brute-force attacks. This issue has been patched in version 0.4.5. Admins w...Show more
BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brute-force attacks. This issue has been patched in version 0.4.5. Admins with existing instances will need to update their `nginx.conf` file that was created when the instance was set up. Users are advised advised to upgrade. Users unable to upgrade may update their nginx.conf files with the changes manually.Show less
1Rapid7
1Velociraptor
Jun 17, 2026
Jul 29, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another c...Show more
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issue was resolved in Velociraptor 0.6.5-2.Show less
1Mb.miniaudioplayer Project
1Mb.miniaudioplayer
Nov 21, 2024
Jul 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplie...Show more
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from behind vulnerable website or to perform otherwise restricted actions and subsequently download files with the extension mp3, mp4a, wav and ogg from anywhere the web server application has read access to the system. WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files version 1.7.6 is vulnerable; prior versions may also be affected.Show less
3Clusterlabs
DebianFedoraproject
3Booth
Debian LinuxFedora
Jun 17, 2026
Jul 28, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from...Show more
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.Show less
1Motorola
1Ace1000 Firmware
Jun 17, 2026
Jul 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engine...Show more
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is controlled by 5 preconfigured accounts (root, abuilder, acelogin, cappl, ace), all of which come with default credentials. Although the ACE1000 documentation mentions the root, abuilder and acelogin accounts and instructs users to change the default credentials, the cappl and ace accounts remain undocumented and thus are unlikely to have their credentials changed.Show less
1Zohocorp
1Manageengine Supportcenter Plus
Jun 17, 2026
Jul 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
1Wavlink
1Wifi Repeater Firmware
Jun 17, 2026
Jul 25, 2022
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml.
1Codexshaper
1Wp Oauth2 Server
Jun 17, 2026
Jul 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.
1Tovyblox
1Tovy
Jun 17, 2026
Jul 22, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including privileged users such as the other of the instance. The problem has been...Show more
Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log in as other users, including privileged users such as the other of the instance. The problem has been patched in version 0.7.51.Show less
1Yikesinc
1Custom Product Tabs For Woocommerce
Jun 17, 2026
Jul 21, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
1Atlassian
11Bamboo
BitbucketConfluence Data Center+8 more
Jun 17, 2026
Jul 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the...Show more
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4.Show less
1Micodus
1Mv720 Firmware
Jun 17, 2026
Jul 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.
1Dw
1Megapix Firmware
Jun 17, 2026
Jul 19, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
1Chcnav
1P5e Gnss Firmware
Jun 17, 2026
Jul 18, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.
1Chcnav
1P5e Gnss Firmware
Jun 17, 2026
Jul 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and pass...Show more
The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.Show less