CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Debian2Debian Linux ShiroJun 17, 2026 Nov 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass. |
A security issue was found in UniFi Protect controller v1.14.10 and earlier.The authentication in the UniFi Protect controller API was using “x-token” improperly, allowing attackers to use the API to send authenticated m...Show more |
1Silver Peak 1Unity Orchestrator Jun 17, 2026 Nov 5, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to Orchestrator by introducing an HTTP HOST...Show more |
Immuta v2.8.2 is affected by one instance of insecure permissions that can lead to user account takeover. |
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it. |
In SonarQube 8.4.2.36762, an external attacker can achieve authentication bypass through SonarScanner. With an empty value for the -D sonar.login option, anonymous authentication is forced. This allows creating and overw...Show more |
1Vmware 1Single Sign On For Tanzu Jun 17, 2026 Oct 31, 2020 N/A· v4 7.9 HIGH· v3 4.6 MEDIUM· v2 Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboar...Show more |
1Hp 1Storeserv Management Console Jun 17, 2026 Oct 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has p...Show more |
FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain complete persistent a...Show more |
1Cisco 1Firepower Threat Defense Jun 17, 2026 Oct 21, 2020 N/A· v4 5.8 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Oct 21, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in the Common Access Card (CAC) authentication feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and access the FMC syste...Show more |
omniauth-auth0 (rubygems) versions >= 2.3.0 and < 2.4.1 improperly validate the JWT token signature when using the `jwt_validator.verify` method. Improper validation of the JWT token signature can allow an attacker to by...Show more |
In Spree before versions 3.7.11, 4.0.4, or 4.1.11, expired user tokens could be used to access Storefront API v2 endpoints. The issue is patched in versions 3.7.11, 4.0.4 and 4.1.11. A workaround without upgrading is des...Show more |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Redhat 3Jboss Enterprise Application Platform Openshift Application RuntimesSingle Sign OnJun 17, 2026 Oct 16, 2020 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an at...Show more |
A vulnerability has been identified in SIPORT MP (All versions < 3.2.1). Vulnerable versions of the device could allow an authenticated attacker to impersonate other users of the system and perform (potentially administr...Show more |
1Lenovo 1Thinkpad Stack Wireless Router Firmware Jun 17, 2026 Oct 14, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 An authentication bypass vulnerability was reported in Lenovo ThinkPad Stack Wireless Router firmware version 1.1.3.4 that could allow escalation of privilege. |
1Huawei 6Laya Al00ep Firmware Mate 20 FirmwareMate 20 X Firmware+3 moreJun 17, 2026 Oct 12, 2020 N/A· v4 4.6 MEDIUM· v3 1.9 LOW· v2 There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain inf...Show more |
1Ibm 1Curam Social Program Management Jun 17, 2026 Oct 12, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A HTTP Verb Tampering vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass security access controls...Show more |
1Netgear 4Gs110emx Firmware Gs810emx FirmwareXs512em Firmware+1 moreJun 17, 2026 Oct 9, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by authentication bypass. This affects GS110EMX before 1.0.1.7, GS810EMX before 1.7.1.3, XS512EM before 1.0.1.3, and XS724EM before 1.0.1.3. |