CWE-287
4,509 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,509)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master. |
1One Church Management System Project 1One Church Management System Jun 17, 2026 Mar 29, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation l...Show more |
1Mirmay 2File Manager Secure Private BrowserNov 21, 2024 Mar 28, 2022 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Affected is the Auto Lock. A race condition leads to a local authentication bypass. The exploit has be...Show more |
1Zyxel 23Atp100 Firmware Atp100w FirmwareAtp200 Firmware+20 moreJun 17, 2026 Mar 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.2...Show more |
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token). |
2Clusterlabs Debian2Debian Linux PcsJun 17, 2026 Mar 25, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accoun...Show more |
1Iptime 9Nas I Firmware Nas Ii FirmwareNas Iie Firmware+6 moreJun 17, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attackers are able to steal important information in the server by exploiting vulnerabilities such as insu...Show more |
D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi. |
2Fedoraproject Redhat3389 Directory Server Enterprise LinuxFedoraJun 17, 2026 Mar 23, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. |
5Broadcom DebianLinux+2 more9Brocade Fabric Operating System Firmware Communications Cloud Native Core Binding Support FunctionDebian Linux+6 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have...Show more |
1Mcafee 1Epolicy Orchestrator Jun 17, 2026 Mar 23, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote attacker to change the password of a compromised session wit...Show more |
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Mar 23, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0. |
An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and cause a Denial of Service (DoS). An attacker without access to securely protected data on a secure U...Show more |
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A local attacker may be able to view the previous...Show more |
3Debian FedoraprojectOpenvpn3Debian Linux FedoraOpenvpnJun 17, 2026 Mar 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be grant...Show more |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Mar 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManag...Show more |
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges. |
Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-alpha.0, a user could have their authentication cookie replaced with an authentication cookie from ano...Show more |
2Debian Openbsd2Debian Linux OpensshJun 17, 2026 Mar 13, 2022 N/A· v4 3.7 LOW· v3 2.6 LOW· v2 An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None aut...Show more |
1Yokogawa 5Centum Cs 3000 Entry Firmware Centum Cs 3000 FirmwareCentum Vp Entry Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10...Show more |