← Back
CWE-287

4,510 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,510)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netgear
17Ac2100 Firmware
Ac2400 FirmwareAc2600 Firmware+14 more
Jun 17, 2026
Jan 25, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists...Show more
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-13313.Show less
2Adodb Project
Debian
2Adodb
Debian Linux
Jun 17, 2026
Jan 25, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.
1Unisys
1Messaging Integration Services
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unisys OS 2200 Messaging Integration Services (NTSI) 7R3B IC3 and IC4, 7R3C, and 7R3D has an Incorrect Implementation of an Authentication Algorithm. An LDAP password is not properly validated.
1Teslamate
1Teslamate
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacke...Show more
TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.Show less
1Phpmyadmin
1Phpmyadmin
Jun 17, 2026
Jan 22, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login insta...Show more
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.Show less
1Fresenius Kabi
6Agilia Connect Firmware
Agilia Partner Maintenance SoftwareLink+ Agilia Firmware+3 more
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the...Show more
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript or intentionally bypass the client-side checks. An attacker with knowledge of the service user could circumvent the client-side control and login with service privileges.Show less
1Fresenius Kabi
6Agilia Connect Firmware
Agilia Partner Maintenance SoftwareLink+ Agilia Firmware+3 more
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.
1Ibm
1Cognos Controller
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could allow a remote attacker to bypass security restrictions, caused by improper validation of authentication cookies. IBM X-Force ID: 190847.
1Lexmark
1Mc3224i Firmware
Jun 17, 2026
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
1Onionshare
1Onionshare
Jun 17, 2026
Jan 18, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write...Show more
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised as another chat participant.Show less
1Onionshare
1Onionshare
Jun 17, 2026
Jan 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated users (or unauthenticated in public mod...Show more
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated users (or unauthenticated in public mode) can send messages without being visible in the list of chat participants. This issue has been resolved in version 2.5.Show less
1Aioseo
1All In One Seo
Jun 17, 2026
Jan 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST AP...Show more
The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could ultimately enable users with low-privileged accounts, like subscribers, to perform remote code execution on affected sites.Show less
1Crestron
1Hd Md4x2 4k E Firmware
Jun 17, 2026
Jan 15, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate...Show more
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI switcher is accessed unauthenticated, user credentials are disclosed that are valid to authenticate to the web interface. Specifically, aj.html sends a JSON document with uname and upassword fields.Show less
1Commvault
1Commcell
Jun 17, 2026
Jan 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within...Show more
This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CVSearchService service. The issue results from the lack of proper validation prior to authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-13706.Show less
1Netgear
1R7000 Firmware
Jun 17, 2026
Jan 13, 2022
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The spec...Show more
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000 1.0.11.116_10.2.100 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SOAP requests. The issue results from the lack of proper authentication verification before performing a password reset. An attacker can leverage this vulnerability to reset the admin password. Was ZDI-CAN-13483.Show less
1Westerndigital
1My Cloud Os
Jun 17, 2026
Jan 13, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access...Show more
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP scripts.Show less
1Discourse
1Discourse
Jun 17, 2026
Jan 13, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` allow some users to log in to a community before they should be able to do...Show more
Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` allow some users to log in to a community before they should be able to do so. A user invited via email to a forum with `must_approve_users` enabled is going to be automatically logged in, bypassing the check that does not allow unapproved users to sign in. They will be able to do everything an approved user can do. If they logout, they cannot log back in. This issue is patched in the `stable` version 2.7.13, `beta` version 2.8.0.beta11, and `tests-passed` version 2.8.0.beta11. One may disable invites as a workaround. Administrators can increase `min_trust_level_to_allow_invite` to reduce the attack surface to more trusted users.Show less
1Dahuasecurity
28Asc2204c Firmware
Hcvr7xxx FirmwareHcvr8xxx Firmware+25 more
Jun 17, 2026
Jan 13, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerability through specific deployments to reset device passwords.
3Debian
FedoraprojectZabbix
3Debian Linux
FedoraZabbix
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configur...Show more
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.Show less
1Apache
1Guacamole
Jun 17, 2026
Jan 11, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.