CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports. |
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attackers to execute the management function without logging in, access members’ information, modi...Show more |
1Ibm 2Infosphere Change Data Capture Infosphere Data ReplicationJun 17, 2026 Jul 16, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Forc...Show more |
iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980. |
1Vmware 2Cloud Foundation EsxiJun 17, 2026 Jul 13, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a s...Show more |
1Mitsubishi 19Ae 200a Firmware Ae 200e FirmwareAe 50a Firmware+16 moreJun 17, 2026 Jul 13, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3.35, GB-50A Ver.2.50 to Ver. 3.35, AG-150A-A Ver.3.20 and prior, AG-150...Show more |
1Nextcloud 1Nextcloud Server Jun 17, 2026 Jul 12, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used user...Show more |
Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies. |
1Fortinet 1Fortinet Single Sign On Jun 17, 2026 Jul 12, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UD...Show more |
EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vulnerability exists in the Edinburgh, Fuji, Geneva, and Hanoi versions of the software. When the Edge...Show more |
Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication. |
Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application. |
1A Stage Inc 2At 40cm01sr Firmware Sct 40cm01sr FirmwareJun 17, 2026 Jul 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary command via telnet. |
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads an...Show more |
1Zyxel 37Usg1000 Firmware Usg100 FirmwareUsg1100 Firmware+34 moreJun 17, 2026 Jul 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which co...Show more |
1Broadcom 8Symantec Advanced Secure Gateway 500 10 Firmware Symantec Advanced Secure Gateway S200 30 FirmwareSymantec Advanced Secure Gateway S200 40 Firmware+5 moreJun 17, 2026 Jun 30, 2021 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypass vulnerability. An unauthenticated attacker can execute arbitrary CLI commands, view/modify the ap...Show more |
A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server 4.0 allows attackers with access to the hashed password to use it without having to crack it. This i...Show more |
1Weidmueller 8Ie Wl Bl Ap Cl Eu Firmware Ie Wl Bl Ap Cl Us FirmwareIe Wl Vl Ap Br Cl Eu Firmware+5 moreJun 17, 2026 Jun 25, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret s...Show more |
2Etinet Hpe2Backbox E4.09 Firmware Backbox H4.09 FirmwareJun 17, 2026 Jun 25, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running BBSV to login to the Backbox UI application, the system procedure (USER_AUTHENTICATE_) used for verif...Show more |
1Vmware 1Carbon Black App Control Jun 17, 2026 Jun 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be a...Show more |