CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be...Show more |
Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link |
1Loxone 1Miniserver Gen 1 Firmware Jun 17, 2026 Jan 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Loxone Miniserver devices with firmware before 11.1 (aka 11.1.9.3) are unable to use an authentication method that is based on the "signature of the update package." Therefore, these devices (or attackers who are spoofin...Show more |
1Nec 2Univerge Sv8500 Firmware Univerge Sv9500 FirmwareJun 17, 2026 Jan 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the informat...Show more |
1Nec 1Baseboard Management Controller Jun 17, 2026 Jan 13, 2021 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 Multiple NEC products (Express5800/T110j, Express5800/T110j-S, Express5800/T110j (2nd-Gen), Express5800/T110j-S (2nd-Gen), iStorage NS100Ti, and Express5800/GT110j) where Baseboard Management Controller (BMC) firmware Re...Show more |
1Microsoft 1Bot Framework Software Development Kit Jun 17, 2026 Jan 12, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Bot Framework SDK Information Disclosure Vulnerability |
The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password requirement for an existing account until the second login occurs. |
1Limit Login Attempts Project 1Limit Login Attempts Nov 21, 2024 Jan 6, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts. |
The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_us...Show more |
1Hgiga 10Msr45 Isherlock Antispam Msr45 Isherlock AuditMsr45 Isherlock Base+7 moreJun 17, 2026 Dec 31, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism. |
NETGEAR DGN2200v1 devices before v1.0.0.60 mishandle HTTPd authentication (aka PSV-2020-0363, PSV-2020-0364, and PSV-2020-0365). |
1Huawei 4Cloudengine 12800 Firmware Cloudengine 5800 FirmwareCloudengine 6800 Firmware+1 moreJun 17, 2026 Dec 29, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by crafting malicious files to...Show more |
An issue was discovered in Zammad before 3.4.1. There is an authentication bypass in the SSO endpoint via a crafted header, when SSO is not configured. An attacker can create a valid and authenticated session that can be...Show more |
1Abb 2Symphony + Historian Symphony + OperationsJun 17, 2026 Dec 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process. |
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality. |
1Emerson 4X Stream Enhanced Xefd Firmware X Stream Enhanced Xegk FirmwareX Stream Enhanced Xegp Firmware+1 moreJun 17, 2026 Dec 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an att...Show more |
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it...Show more |
1Trendmicro 1Interscan Web Security Virtual Appliance Jun 17, 2026 Dec 17, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-...Show more |
1Magic Home Pro Project 1Magic Home Pro Jun 17, 2026 Dec 17, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Magic Home Pro application 1.5.1 for Android allows Authentication Bypass. The security control that the application currently has in place is a simple Username and Password authentication function. Using enumeration...Show more |
IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516. |