← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tcman
1Gim
Jun 17, 2026
Dec 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information.
1Elabftw
1Elabftw
Jun 17, 2026
Dec 16, 2021
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single...Show more
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such as LDAP or SAML. It impacts instances where LDAP or SAML is used for authentication instead of the (default) local password mechanism. Users should upgrade to at least version 4.2.0.Show less
1Elabftw
1Elabftw
Jun 17, 2026
Dec 16, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrary accounts by setting a specially crafte...Show more
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address. This vulnerability impacts all instances that have not set an explicit email domain name allowlist. Note that whereas neither administrators nor targeted users are notified of a change, an attacker will need to control an account. The default settings require administrators to validate newly created accounts. The problem has been patched. Users should upgrade to at least version 4.2.0. For users unable to upgrade enabling an email domain allow list (from Sysconfig panel, Security tab) will completely resolve the issue.Show less
1Baxter
7Welch Allyn Connex Cardio
Welch Allyn Diagnostic Cardiology SuiteWelch Allyn Hscribe Holter Analysis System Firmware+4 more
Jun 17, 2026
Dec 15, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provision...Show more
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.Show less
1Metagauss
1Registrationmagic
Jun 17, 2026
Dec 14, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the...Show more
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.Show less
1Glfusion
1Glfusion
Jun 17, 2026
Dec 14, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to register, they will find that the mailb...Show more
glFusion CMS v1.7.9 is affected by an arbitrary user registration vulnerability in /public_html/users.php. An attacker can register with the mailbox of any user. When users want to register, they will find that the mailbox has been occupied.Show less
1Siemens
2Sipass Integrated
Siveillance Identity
Jun 17, 2026
Dec 14, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identit...Show more
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications insufficiently limit the access to the internal user authentication service. This could allow an unauthenticated remote attacker to trigger several actions on behalf of valid user accounts.Show less
1Ibm
1Spectrum Copy Data Management
Jun 17, 2026
Dec 13, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Dec 9, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
1Dpgaspar
1Flask Appbuilder
Jun 17, 2026
Dec 9, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted...Show more
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.Show less
1Anker
1Eufy Homebase 2 Firmware
Jun 17, 2026
Dec 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attac...Show more
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.Show less
1Gryphonconnect
1Gryphon Tower Firmware
Jun 17, 2026
Dec 9, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same...Show more
Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make configuration changes to, or otherwise attack victims' devices as though they were on an adjacent network.Show less
1Fortinet
1Fortiauthenticator
Jun 17, 2026
Dec 9, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal.
1Synel
2Eharmonynew
Synel Reports
Jun 17, 2026
Dec 8, 2021
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The...Show more
SYNEL - eharmonynew / Synel Reports - The attacker can log in to the system with default credentials and export a report of eharmony system with sensetive data (Employee name, Employee ID number, Working hours etc') The vulnerabilety has been addressed and fixed on version 11. Default credentials , Security miscommunication , Sensetive data exposure vulnerability in Synel Reports of SYNEL eharmonynew, Synel Reports allows an attacker to log into the system with default credentials. This issue affects: SYNEL eharmonynew, Synel Reports 8.0.2 version 11 and prior versions.Show less
1Huawei
3Emui
HarmonyosMagic Ui
Jun 17, 2026
Dec 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
1Atlassian
1Jira Software Data Center
Jun 17, 2026
Dec 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication v...Show more
Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/roles endpoint. The affected versions are before version 8.19.1.Show less
1Atlassian
1Jira Software Data Center
Jun 17, 2026
Dec 8, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authent...Show more
Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs of another user's Jira Service Management project via a Broken Authentication vulnerability in the /plugins/servlet/audit/resource endpoint. The affected versions of Jira Server and Data Center are before version 8.19.1.Show less
1Mahadiscom
1Mahavitaran
Jul 9, 2026
Dec 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function
1Goautodial
2Goautodial
Goautodial Api
Jun 17, 2026
Dec 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerabl...Show more
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 exposes an API router that accepts a username, password, and action that routes to other PHP files that implement the various API functions. Vulnerable versions of GOautodial validate the username and password incorrectly, allowing the caller to specify any values for these parameters and successfully authenticate. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:CShow less
1Huawei
1Harmonyos
Jun 17, 2026
Dec 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed.