CWE-287
4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,504)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity. |
A vulnerability was found in Klapp App and classified as problematic. This issue affects some unknown processing of the JSON Web Token Handler. The manipulation leads to weak authentication. The attack may be initiated r...Show more |
1Platinumchina 1Platinum Mobile Jun 17, 2026 Jun 7, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability, which was classified as critical, was found in Platinum Mobile 1.0.4.850. Affected is /MobileHandler.ashx which leads to broken access control. The attack requires authentication. Upgrading to version 1....Show more |
1Schneider Electric 2Wiser Smart Eer21000 Firmware Wiser Smart Eer21001 FirmwareJun 17, 2026 Jun 2, 2022 N/A· v4 8.8 HIGH· v3 7.5 HIGH· v2 A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a session. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior) |
1Owllabs 1Meeting Owl Pro Firmware Jun 17, 2026 Jun 2, 2022 N/A· v4 7.1 HIGH· v3 4.3 MEDIUM· v2 Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is used. |
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RP...Show more |
1Barco 1Control Room Management Suite Jun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication. |
1Chat Server Project 1Chat Server Jun 17, 2026 May 31, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authP...Show more |
TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the au...Show more |
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 15.5. A local user may be able to enable iCloud Photos without authentication. |
5Brocade DebianHaxx+2 more12Bootstrap Os Clustered Data OntapCurl+9 moreJun 17, 2026 May 26, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the...Show more |
1Dell 1Supportassist Os Recovery Jun 17, 2026 May 26, 2022 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery...Show more |
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC...Show more |
1Airfield Online Project 1Airfield Online Jun 17, 2026 May 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /backups/ of the MySQL backup handler. An attacker is able to get access to sensitive data without prop...Show more |
1Telecomsoftware 2Samwin Agent Samwin Contact CenterNov 21, 2024 May 24, 2022 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vulnerability affects the function passwordScramble in the library SAMwinLIBVB.dll of the component Pas...Show more |
Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10.14 and 11.7, users could pass along URLs for files belonging to organizations other than the user's...Show more |
1Zyxel 32Atp100 Firmware Atp100w FirmwareAtp200 Firmware+29 moreJun 17, 2026 May 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21...Show more |
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions 2.1.15, 2.2.9, and 2.3.4 which would all...Show more |
1Sooteway Wi Fi Range Extender Project 1Sooteway Wi Fi Range Extender Jun 17, 2026 May 20, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely. |
1Siemens 367kg8500 0aa00 0aa0 Firmware 7kg8500 0aa00 2aa0 Firmware7kg8500 0aa10 0aa0 Firmware+33 moreJun 17, 2026 May 20, 2022 6.9 MEDIUM· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not restrict unauthenticated access to certain pages of the web interface. This could allow an attacker to delete log files withou...Show more |