CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Phpgurukul 1Hospital Management System Jun 17, 2026 Jun 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information. |
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors. |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an a...Show more |
1Apollosapp 1Data Connector Rock Jun 17, 2026 Jun 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new user registrations are able to access anyone's account by only knowing their basic profile informat...Show more |
1Cisco 9Sf220 24 Firmware Sf220 24p FirmwareSf220 48 Firmware+6 moreJun 17, 2026 Jun 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more |
1Cisco 9Sf220 24 Firmware Sf220 24p FirmwareSf220 48 Firmware+6 moreJun 17, 2026 Jun 16, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more |
1Cisco 9Sf220 24 Firmware Sf220 24p FirmwareSf220 48 Firmware+6 moreJun 17, 2026 Jun 16, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more |
1Cisco 9Sf220 24 Firmware Sf220 24p FirmwareSf220 48 Firmware+6 moreJun 17, 2026 Jun 16, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root use...Show more |
1Sap 2Netweaver Abap Netweaver Application Server AbapJun 17, 2026 Jun 16, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format,...Show more |
1Posimyth 1The Plus Addons For Elementor Jun 17, 2026 Jun 14, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password e...Show more |
1Schneider Electric 4Powerlogic Pm5560 Firmware Powerlogic Pm5561 FirmwarePowerlogic Pm5562 Firmware+1 moreJun 17, 2026 Jun 11, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connec...Show more |
1Samsung 9Galaxy Watch 3 Firmware Galaxy Watch Active 2 FirmwareGalaxy Watch Active Firmware+6 moreJun 17, 2026 Jun 11, 2021 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness. |
Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication. |
An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre-logon profile switch button within the Windows logon screen enabled, is able to drop to an administ...Show more |
1Intel 2Realsense Id F450 Firmware Realsense Id F455 FirmwareJun 17, 2026 Jun 9, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access. |
1Bosch 3Cpp6 Firmware Cpp7.3 FirmwareCpp7 FirmwareJun 17, 2026 Jun 9, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Onl...Show more |
In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authentication. |
1Chiyu Tech 10Bf 430 Firmware Bf 431 FirmwareBf 450m Firmware+7 moreJun 17, 2026 Jun 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially...Show more |
OpenVPN Access Server 2.8.7 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially tri...Show more |
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already ex...Show more |