CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Apple 6Ipados Iphone OsMacos+3 moreJun 17, 2026 Sep 8, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious website may be able to access restricted por...Show more |
1Qualcomm 267Apq8009 Firmware Apq8017 FirmwareApq8053 Firmware+264 moreJun 17, 2026 Sep 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics C...Show more |
1Qualcomm 126Apq8053 Firmware Apq8064au FirmwareApq8096au Firmware+123 moreJun 17, 2026 Sep 8, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Ele...Show more |
pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to use the REST API to capture and download packets with no capture filter...Show more |
1Cisco 1Enterprise Nfv Infrastructure Software Jun 17, 2026 Sep 2, 2021 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication a...Show more |
1Christiedigital 1Dwu850 Gs Firmware Jun 17, 2026 Sep 1, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafted query containing an unspecified Cookie header. Authentication bypass can be achieved by including...Show more |
1Vmware 4Cloud Foundation Identity ManagerVrealize Suite Lifecycle Manager+1 moreJun 17, 2026 Aug 31, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 c...Show more |
A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained access to a network to subsequently control the Protect camera(s) assigned to said network. This vul...Show more |
1Wago 12750 362 Firmware 750 363 Firmware750 823 Firmware+9 moreJun 17, 2026 Aug 31, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAGO PLCs in firmware ve...Show more |
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNAPSHOT allow anyone that can connect to the server to forge a LoginPacket with manipulated JWT token...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Aug 30, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. |
1Midnight Commander 1Midnight Commander Jun 17, 2026 Aug 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the a...Show more |
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with admini...Show more |
1Vmware 3Cloud Foundation Vrealize Operations ManagerVrealize Suite Lifecycle ManagerJun 17, 2026 Aug 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operatio...Show more |
Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in the `SearchableTrait#scopeSearch()`. Attackers without authentication can utilize this vulnerability t...Show more |
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially...Show more |
octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can exploit this vulnerability to bypass authentication and takeover of and user account on...Show more |
1Apple 3Ipados Iphone OsMacosJun 17, 2026 Aug 24, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The issue was addressed with improved authentication. This issue is fixed in iOS 15 and iPadOS 15. A malicious application may be able to access photo metadata without needing permission to access photos. |
WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation. |
1Parseplatform 1Parse Server Jun 17, 2026 Aug 19, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup users and also allow users to login anonymously. Prior to version 4.5.1, w...Show more |