← Back
CWE-287

4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Sports Complex Booking System Project
1Online Sports Complex Booking System
Jun 17, 2026
May 20, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POST request.
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Jun 17, 2026
May 18, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
1Dlink
1Dir 816l Firmware
Jun 17, 2026
May 18, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.
12code
1Wpqa Builder
Jun 17, 2026
May 16, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to...Show more
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user, allowing any users (with privileges as low as Subscriber) to delete the profile pictures of any other user.Show less
1Sysaid
1Sysaid
Jun 17, 2026
May 12, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp wi...Show more
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.Show less
1Intel
7Optane Memory H10 With Solid State Storage Firmware
Optane Memory H20 With Solid State Storage FirmwareOptane Ssd 900p Firmware+4 more
Jun 17, 2026
May 12, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Improper authentication in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow an privileged user to potentially enable information disclosure via lo...Show more
Improper authentication in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow an privileged user to potentially enable information disclosure via local access.Show less
1Ibm
1In Band Manageability
Jun 17, 2026
May 12, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.
1Requarks
1Wiki.js
Jun 17, 2026
May 12, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions
1Gitlab
1Gitlab
Jun 17, 2026
May 11, 2022
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly aut...Show more
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of information which allowed an user to authenticate without a personal access token.Show less
2Gok
Tecson
5E Litro Net Firmware
Lx Net FirmwareLx Q Net Firmware+2 more
Jun 17, 2026
May 6, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access ri...Show more
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.Show less
1Splunk
1Splunk
Jun 17, 2026
May 6, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise insta...Show more
A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA and does not impact or affect a DUO product or service.Show less
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
May 6, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions...Show more
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.Show less
1Qnap
1Photo Station
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed th...Show more
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 ( 2022/02/11 ) and later Photo Station 5.4.13 ( 2022/02/11 ) and laterShow less
1Qnap
1Video Station
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed th...Show more
An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 and later Video Station 5.3.13 and later Video Station 5.1.8 and laterShow less
1Parseplatform
1Parse Server
Jun 17, 2026
May 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by...Show more
Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks of the resource the URL points to before downloading it.Show less
1Samsung
1Link To Windows Service
Jun 17, 2026
May 3, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.
1Logitech
1Options
Jun 17, 2026
May 3, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
1Pingidentity
1Pingone Mfa Integration Kit
Jun 17, 2026
May 2, 2022
N/A· v4
7.7 HIGH· v3
5.0 MEDIUM· v2
An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used as part of an authentication flow.
1Pingidentity
1Pingfederate
Jun 17, 2026
May 2, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s passwor...Show more
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user can reset another existing user’s password.Show less
1Pingidentity
1Pingid Integration For Windows Login
Jun 17, 2026
Apr 30, 2022
N/A· v4
5.6 MEDIUM· v3
1.9 LOW· v2
A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.