← Back
CWE-287

4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Melag
1Ftp Server
Jun 17, 2026
Jun 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.
1Xisnd
1S&d Smarthome
Jun 17, 2026
Jun 23, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment i...Show more
Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor control.Show less
1Shinasys
3Sihas Acm 300 Firmware
Sihas Gcm 300 FirmwareSihas Sgw 300 Firmware
Jun 17, 2026
Jun 23, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
1Ispyconnect
1Ispy
Jun 17, 2026
Jun 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
1Siemens
4Cerberus Dms
Desigo CcDesigo Cc Compact+1 more
Jun 17, 2026
Jun 21, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All...Show more
A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA V3.18 (All versions in non-default configuration). Affected applications use client-side only authentication, when neither server-side authentication (SSA) nor Kerberos authentication is enabled. In this configuration, attackers could impersonate other users or exploit the client-server protocol without being authenticated.Show less
1Very Simple Contact Form Project
1Very Simple Contact Form
Jun 17, 2026
Jun 20, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypas...Show more
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for spam bots.Show less
1Parseplatform
1Parse Server
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validate...Show more
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be bypassed by making a fake certificate accessible via certain Apple domains and providing the URL to that certificate in an authData object. Versions 4.0.11 and 5.2.2 prevent this by introducing a new `rootCertificateUrl` property to the Parse Server Apple Game Center auth adapter which takes the URL to the root certificate of Apple's Game Center authentication certificate. If no value is set, the `rootCertificateUrl` property defaults to the URL of the current root certificate as of May 27, 2022. Keep in mind that the root certificate can change at any time and that it is the developer's responsibility to keep the root certificate URL up-to-date when using the Parse Server Apple Game Center auth adapter. There are no known workarounds for this issue.Show less
1Grafana
1Grafana
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability
1Ge
1Voluson S8 Firmware
Jun 17, 2026
Jun 17, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibili...Show more
A vulnerability classified as problematic has been found in GE Voluson S8. Affected is the file /uscgi-bin/users.cgi of the Service Browser. The manipulation leads to improper authentication and elevated access possibilities. It is possible to launch the attack on the local host.Show less
1Bittorrent
1Utorrent
Nov 21, 2024
Jun 17, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads to weak authentication. The attack can be initiated remotely. The exploi...Show more
A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads to weak authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.Show less
1Broadcom
1Ca Automic Automation
Jun 17, 2026
Jun 16, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.
1Dlink
1Dir 850l Firmare
Nov 21, 2024
Jun 16, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data F...Show more
An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data Frames to the AP without encryption.Show less
1Opcfoundation
1Ua .net Standard Stack
Jun 17, 2026
Jun 16, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.
1Cisco
2Email Security Appliance
Secure Email And Web Manager
Jun 17, 2026
Jun 15, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an una...Show more
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and log in to the web management interface of an affected device. This vulnerability is due to improper authentication checks when an affected device uses Lightweight Directory Access Protocol (LDAP) for external authentication. An attacker could exploit this vulnerability by entering a specific input on the login page of the affected device. A successful exploit could allow the attacker to gain unauthorized access to the web-based management interface of the affected device.Show less
1Cisco
1Identity Services Engine
Jun 17, 2026
Jun 15, 2022
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is...Show more
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.Show less
1Siemens
1Sicam Gridedge Essential
Jun 17, 2026
Jun 14, 2022
8.6 HIGH· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attack...Show more
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does not require authenticated access for privileged functions. This could allow an unauthenticated attacker to change data of a user, such as credentials, in case that user's id is known.Show less
1Qualcomm
81Aqt1000 Firmware
Qca6390 FirmwareQca6391 Firmware+78 more
Jun 17, 2026
Jun 14, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdrago...Show more
Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon MobileShow less
1Huawei
1Flmg 10 Firmware
Jun 17, 2026
Jun 13, 2022
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a control of the victim device.