CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Asus 2Gt Ac2900 Firmware Lyra Mini FirmwareJun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to u...Show more |
1Openmptcprouter 1Openmptcprouter Jun 17, 2026 May 6, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing a...Show more |
1Cisco 2Catalyst Sd Wan Manager Sd Wan VmanageJun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to ga...Show more |
1Projectworlds 1Online Book Store Project In Php Jun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication and obtain sensitive information. |
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to manipulate the use...Show more |
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks. |
1Buffalo 2Wsr 2533dhp3 Bk Firmware Wsr 2533dhpl2 Bk FirmwareJun 17, 2026 Apr 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor. |
A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this secu...Show more |
1Ave 753ab Wbs Firmware DominaplusTs01 Firmware+4 moreJun 17, 2026 Apr 28, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the autologin value to 1 allo...Show more |
The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the Go XML parser which can cause SAML authentication bypass. This is because the XML parser doesn’t gua...Show more |
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow...Show more |
1Mitsubishielectric 6Got2000 Gt25 Firmware Got2000 Gt27 FirmwareGs2107 Wtbd N Firmware+3 moreJun 17, 2026 Apr 22, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 series GT25 model VNC server versions 01.39.010 and prior, GOT2000 series GT21 model GT2107-WTBD VNC ser...Show more |
1Abus 1Secvest Wireless Alarm System Fuaa50000 Firmware Jun 17, 2026 Apr 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ABUS Secvest wireless alarm system FUAA50000 (v3.01.17) fails to properly authenticate some requests to its built-in HTTPS interface. Someone can use this vulnerability to obtain sensitive information from the system...Show more |
A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient authentication validation. |
1Atlassian 1Connect Spring Boot Jun 17, 2026 Apr 16, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect Spring Boot is a Java Spring Boot package for building Atlassian Connect apps. Authentication betwe...Show more |
Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian produ...Show more |
4Debian FedoraprojectLinuxfoundation+1 more4Ceph Ceph StorageDebian Linux+1 moreJun 17, 2026 Apr 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_...Show more |
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities. |
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username t...Show more |
1Microfocus 1Netiq Advanced Authentication Jun 17, 2026 Apr 12, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue. |