← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpgurukul
1Hospital Management System
Jun 17, 2026
Jun 22, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.
1Weseek
1Growi
Jun 17, 2026
Jun 22, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.
1Sensiolabs
1Symfony
Jun 17, 2026
Jun 17, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an a...Show more
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application defines multiple firewalls, the token authenticated by one of the firewalls was available for all other firewalls. This could be abused when the application defines different providers for each part of the application, in such a situation, a user authenticated on a part of the application could be considered authenticated on the rest of the application. Starting in version 5.3.2, a patch ensures that the authenticated token is only available for the firewall that generates it.Show less
1Apollosapp
1Data Connector Rock
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile informat...Show more
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within the app, as well as any authenticated links to Rock-based webpages (such as giving and events). There is a patch in version 2.20.0. As a workaround, one can patch one's server by overriding the `create` data source method on the `People` class.Show less
1Cisco
9Sf220 24 Firmware
Sf220 24p FirmwareSf220 48 Firmware+6 more
Jun 17, 2026
Jun 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
9Sf220 24 Firmware
Sf220 24p FirmwareSf220 48 Firmware+6 more
Jun 17, 2026
Jun 16, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
9Sf220 24 Firmware
Sf220 24p FirmwareSf220 48 Firmware+6 more
Jun 17, 2026
Jun 16, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
9Sf220 24 Firmware
Sf220 24p FirmwareSf220 48 Firmware+6 more
Jun 17, 2026
Jun 16, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Sap
2Netweaver Abap
Netweaver Application Server Abap
Jun 17, 2026
Jun 16, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format,...Show more
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system.Show less
1Posimyth
1The Plus Addons For Elementor
Jun 17, 2026
Jun 14, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password e...Show more
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password email to a registered user on behalf of the WordPress site. Such issue could be chained with an open redirect (CVE-2021-24358) in version below 4.1.10, to include a crafted password reset link in the email, which would lead to an account takeover.Show less
1Schneider Electric
4Powerlogic Pm5560 Firmware
Powerlogic Pm5561 FirmwarePowerlogic Pm5562 Firmware+1 more
Jun 17, 2026
Jun 11, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connec...Show more
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.Show less
1Samsung
9Galaxy Watch 3 Firmware
Galaxy Watch Active 2 FirmwareGalaxy Watch Active Firmware+6 more
Jun 17, 2026
Jun 11, 2021
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.
1Netsetman
1Netsetman
Jun 17, 2026
Jun 10, 2021
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administ...Show more
An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administrative shell and execute arbitrary commands as SYSTEM via the "save log to file" feature. To accomplish this, the attacker can navigate to cmd.exe.Show less
1Intel
2Realsense Id F450 Firmware
Realsense Id F455 Firmware
Jun 17, 2026
Jun 9, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
1Bosch
3Cpp6 Firmware
Cpp7.3 FirmwareCpp7 Firmware
Jun 17, 2026
Jun 9, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Onl...Show more
A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are affected by this vulnerability. Versions 7.62 or lower and INTEOX cameras are not affected.Show less
1Silverstripe
1Silverstripe
Jun 17, 2026
Jun 8, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication.
1Chiyu Tech
10Bf 430 Firmware
Bf 431 FirmwareBf 450m Firmware+7 more
Jun 17, 2026
Jun 4, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially...Show more
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.Show less
1Openvpn
1Openvpn Access Server
Jun 17, 2026
Jun 4, 2021
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially tri...Show more
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.Show less
1Redhat
1Satellite
Jun 17, 2026
Jun 2, 2021
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already ex...Show more
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.Show less