← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
1Global Management System
Jun 17, 2026
Apr 10, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
1Samsung
1Experience Service
Jun 17, 2026
Apr 9, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.
1Microfocus
1Operations Bridge Manager
Jun 17, 2026
Apr 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get un...Show more
Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 and 2020.10. The vulnerability could allow remote attackers to bypass user authentication and get unauthorized access.Show less
1Learnsite Project
1Learnsite
Jun 17, 2026
Apr 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the initial letter of the key of a user cookie, the key of the administrator...Show more
Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() function. By modifying the initial letter of the key of a user cookie, the key of the administrator cookie can be obtained.Show less
1Mitake
1Smart Stock Selection
Jun 17, 2026
Apr 8, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in the URL, remote attackers can gain the privileged permissions to access transaction record, and fraudu...Show more
Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in the URL, remote attackers can gain the privileged permissions to access transaction record, and fraudulent trading without login.Show less
1Cisco
9Rv160 Firmware
Rv160w FirmwareRv260 Firmware+6 more
Jun 17, 2026
Apr 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected...Show more
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
3Debian
FedoraprojectMediawiki
3Debian Linux
FedoraMediawiki
Jun 17, 2026
Apr 6, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally...Show more
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the token by an unauthorized party.Show less
1Posimyth
1The Plus Addons For Elementor
Jun 17, 2026
Apr 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin...Show more
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.Show less
1Sannce
1Smart Hd Wifi Security Camera Ean 2 950004 595317 Firmware
Jun 17, 2026
Apr 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over UDP. However, the device offers many more services that also enable str...Show more
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over UDP. However, the device offers many more services that also enable streaming. Although the service used by the mobile application requires a password, the other streaming services do not. By initiating communication on the RTSP port, an attacker can obtain access to the video feed without authenticating.Show less
1Dmasoftlab
1Dma Radius Manager
Jun 17, 2026
Apr 2, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other w...Show more
DMA Softlab Radius Manager 4.4.0 assigns the same session cookie to every admin session. The cookie is valid when the admin is logged in, but is invalid (temporarily) during times when the admin is logged out. In other words, the cookie is functionally equivalent to a static password, and thus provides permanent access if stolen.Show less
1Devolutions
1Devolutions Server
Jun 17, 2026
Apr 1, 2021
N/A· v4
8.1 HIGH· v3
4.9 MEDIUM· v2
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.
1Vmware
1Carbon Black Cloud Workload
Jun 17, 2026
Apr 1, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud...Show more
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.Show less
2Arubanetworks
Siemens
2Instant
Scalance W1750d Firmware
Jun 17, 2026
Mar 29, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.15 and below; Aruba...Show more
A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.18 and below; Aruba Instant 6.5.x: 6.5.4.15 and below; Aruba Instant 8.3.x: 8.3.0.11 and below; Aruba Instant 8.4.x: 8.4.0.5 and below; Aruba Instant 8.5.x: 8.5.0.6 and below; Aruba Instant 8.6.x: 8.6.0.2 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.Show less
1Kongchuanhujiao Project
1Kongchuanhujiao
Jun 17, 2026
Mar 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnerability. All users are impacted. This is fixed in version 1.3.21.
1Hashicorp
1Terraform Enterprise
Jun 17, 2026
Mar 26, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users within an organization to have two-factor authentication enabled. Fixed in v202103-1.
1Samsung
1Cloud
Jun 17, 2026
Mar 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.
1Microfocus
1Access Manager
Jun 17, 2026
Mar 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Authentication Bypass Vulnerability in Micro Focus Access Manager Product, affects all version prior to version 4.5.3.3. The vulnerability could cause information leakage.
1Atlassian
3Data Center
JiraJira Server
Jun 17, 2026
Mar 22, 2021
N/A· v4
7.2 HIGH· v3
6.4 MEDIUM· v2
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget reso...Show more
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.Show less
1Inspireui
1Mstore Api
Jun 17, 2026
Mar 18, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email...Show more
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.Show less
1Eic
1E Document System
Jun 17, 2026
Mar 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the sys...Show more
EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privileged permissions and execute arbitrary commends.Show less