CWE-287
4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,504)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username. |
Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment i...Show more |
1Shinasys 3Sihas Acm 300 Firmware Sihas Gcm 300 FirmwareSihas Sgw 300 FirmwareJun 17, 2026 Jun 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device. |
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL. |
1Siemens 4Cerberus Dms Desigo CcDesigo Cc Compact+1 moreJun 17, 2026 Jun 21, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All...Show more |
1Very Simple Contact Form Project 1Very Simple Contact Form Jun 17, 2026 Jun 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypas...Show more |
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validate...Show more |
Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability |
A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibili...Show more |
A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads to weak authentication. The attack can be initiated remotely. The exploi...Show more |
1Broadcom 1Ca Automic Automation Jun 17, 2026 Jun 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands. |
An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data F...Show more |
1Opcfoundation 1Ua .net Standard Stack Jun 17, 2026 Jun 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials. |
1Microsoft 5Windows 10 Windows 11Windows Server 2016+2 moreJun 17, 2026 Jun 15, 2022 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability |
1Johnsoncontrols 3Metasys Application And Data Server Metasys Extended Application And Data ServerMetasys Open Application ServerJun 17, 2026 Jun 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change. |
1Cisco 2Email Security Appliance Secure Email And Web ManagerJun 17, 2026 Jun 15, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an una...Show more |
1Cisco 1Identity Services Engine Jun 17, 2026 Jun 15, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is...Show more |
1Siemens 1Sicam Gridedge Essential Jun 17, 2026 Jun 14, 2022 8.6 HIGH· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attack...Show more |
1Qualcomm 81Aqt1000 Firmware Qca6390 FirmwareQca6391 Firmware+78 moreJun 17, 2026 Jun 14, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdrago...Show more |
There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a control of the victim device. |