CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event. |
In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execut...Show more |
2Fedoraproject Grafana2Fedora GrafanaJun 17, 2026 Oct 5, 2021 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/sn...Show more |
Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the application, the validity of the password is checked locally. All communication to the database backend i...Show more |
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLab through git and API through access tokens acquired before password ex...Show more |
1Bosch 12Rexroth Indramotion Mlc L20 Firmware Rexroth Indramotion Mlc L25 FirmwareRexroth Indramotion Mlc L40 Firmware+9 moreJun 17, 2026 Oct 4, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login t...Show more |
An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path. |
1Ibm 1Cloud Pak For Security Jun 17, 2026 Sep 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282. |
An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign arbitrary Policy and Object modules via crafted requests to the request handler. |
1Ecoa 3Ecs Router Controller Ecs Firmware Riskbuster FirmwareRiskterminatorJun 17, 2026 Sep 30, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie poisoning can remotely bypass authentication and disclose sensitive information and circumvent physical...Show more |
1Couchbase 1Couchbase Server Jun 17, 2026 Sep 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513. |
1Spomky Labs 1Webauthn Framwork Jun 17, 2026 Sep 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the...Show more |
1Openvpn Monitor Project 1Openvpn Monitor Jun 17, 2026 Sep 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients. |
2D Link Dlink2Dcs 5000l Firmware Dcs 932l FirmwareJun 17, 2026 Sep 24, 2021 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configurat...Show more |
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner group...Show more |
2Infinispan Redhat2Data Grid Infinispan Server RestJun 17, 2026 Sep 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication met...Show more |
1Digi 1Portserver Ts 16 Firmware Jun 17, 2026 Sep 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Rack device do not require authentication or authentication tokens. This vulnerability could allow an...Show more |
1Xss Hunter Express Project 1Xss Hunter Express Jun 17, 2026 Sep 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths. |
2Apache Oracle2Financial Services Crime And Compliance Management Studio ShiroJun 17, 2026 Sep 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0. |
1Dahuasecurity 18Ipc Hum7xxx Firmware Ipc Hx3xxx FirmwareIpc Hx5xxx Firmware+15 moreJun 17, 2026 Sep 15, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets. |