CWE-287
4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,504)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability. |
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.1, users can bypass a lock on the Nextcloud app on an Android device by repeatedly reopening the app....Show more |
2Fedoraproject Freerdp2Fedora FreerdpJun 17, 2026 Apr 26, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an i...Show more |
2Fedoraproject Freerdp3Extra Packages For Enterprise Linux FedoraFreerdpJun 17, 2026 Apr 26, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue a...Show more |
1Veryfitpro Project 1Veryfitpro Jul 9, 2026 Apr 25, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of pass...Show more |
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused usi...Show more |
An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header. |
1Atlassian 3Jira Data Center Jira ServerJira Service ManagementJun 17, 2026 Apr 20, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, v...Show more |
Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attackers to send the RTSP requests using ffplay command and lead to leakage...Show more |
1Abacus 5Abacus Erp 2018 Abacus Erp 2019Abacus Erp 2020+2 moreJun 17, 2026 Apr 19, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15; v2021 versions...Show more |
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then instead of being inactive, any password will successfully match during authentication. This flaw al...Show more |
1Django Mfa3 Project 1Django Mfa3 Jun 17, 2026 Apr 15, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 django-mfa3 is a library that implements multi factor authentication for the django web framework. It achieves this by modifying the regular login view. Django however has a second login view for its admin area. This sec...Show more |
1Cisco 2Wireless Lan Controller 8.10.151.0 Wireless Lan Controller 8.10.162.0Jun 17, 2026 Apr 15, 2022 N/A· v4 10.0 CRITICAL· v3 9.3 HIGH· v2 A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the m...Show more |
1Yokogawa 2B/m9000 Vp Centum VpJun 17, 2026 Apr 15, 2022 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM VP R6.01.10 to R6.09.00, CENTUM VP Small R6.01.10 to R6.09.00, CENTUM VP Basic R6.01.10 to R6.09.00,...Show more |
1Vmware 3Identity Manager Vrealize AutomationWorkspace One AccessJun 17, 2026 Apr 13, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation...Show more |
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials. |
Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard. |
Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission. |
Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication. |
Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting. |