CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This could lead to remote information disclosure with no additional execution p...Show more |
1Medtronic 1Mycarelink Smart Model 25000 Firmware Jun 17, 2026 Dec 14, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Medtronic MyCareLink Smart 25000 contains an authentication protocol vulnerability where the method used to authenticate between the MCL Smart Patient Reader and the Medtronic MyCareLink Smart mobile app is vulnerable...Show more |
Improper Authentication vulnerability in Gallagher Command Centre Server allows an unauthenticated remote attacker to create items with invalid configuration, potentially causing the server to crash and fail to restart....Show more |
In the Macally WIFISD2-2A82 Media and Travel Router 2.000.010, the Guest user is able to reset its own password. This process has a vulnerability which can be used to take over the administrator account and results in sh...Show more |
An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The password authentication for unlocking can be bypassed by forcing the authentication result to be...Show more |
An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The PIN authentication for unlocking can be bypassed by forcing the authentication result to be true...Show more |
1Westerndigital 1My Cloud Os 5 Jun 17, 2026 Dec 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device. |
3Debian FedoraprojectSympa3Debian Linux FedoraSympaJun 17, 2026 Dec 10, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun. |
This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and refresh values to be incorrectly validated, causing the application to tr...Show more |
SAP HANA Database, version - 2.0, does not correctly validate the username when performing SAML bearer token-based user authentication. It is possible to manipulate a valid existing SAML bearer token to authenticate as a...Show more |
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users. |
1Hp 1Edgeline Infrastructure Manager Jun 17, 2026 Dec 2, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authe...Show more |
1Westerndigital 1My Cloud Os 5 Jun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a coo...Show more |
1Westerndigital 1My Cloud Os 5 Jun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a coo...Show more |
1Westerndigital 1My Cloud Os 5 Jun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device. |
1Schneider Electric 16140cpu65260 Firmware 140noc77101 Firmware140noc78000 Firmware+13 moreJun 17, 2026 Dec 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CWE-287: Improper Authentication vulnerability exists which could cause the execution of
commands on the webserver without authentication when sending specially crafted HTTP
requests. |
1Lock Password Manager Safe App Project 1Lock Password Manager Safe App Jun 17, 2026 Nov 30, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical access can unlock the password manager without knowing the master password set by the user. |
1Fujitsu 1Eternus Storage Dx200 S4 Firmware Jun 17, 2026 Nov 30, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI c...Show more |
1Vsolcn 5V1600d Mini Firmware V1600d4l FirmwareV1600d Firmware+2 moreJun 17, 2026 Nov 29, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. It is possible to elevate the privilege of a CLI user (to...Show more |
1Barco 1Wepresent Wipg 1600w Firmware Jun 17, 2026 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the we...Show more |