← Back
CWE-287

4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,511)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Smartstore
1Smartstore
Jun 17, 2026
Oct 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartst...Show more
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
1Soplanning
1Soplanning
Jun 17, 2026
Oct 7, 2020
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.
1Wavlink
1Wn530h4 Firmware
Jun 17, 2026
Oct 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service vi...Show more
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.Show less
1Wpo365
1Wordpress + Azure Ad / Microsoft Office 365
Jun 17, 2026
Oct 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
1Jwt Go Project
1Jwt Go
Jun 17, 2026
Sep 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by the specification). Because the type assertion fails, "" is the value o...Show more
jwt-go before 4.0.0-preview1 allows attackers to bypass intended access restrictions in situations with []string{} for m["aud"] (which is allowed by the specification). Because the type assertion fails, "" is the value of aud. This is a security problem if the JWT token is presented to a service that lacks its own audience check.Show less
1Apache
1Hadoop
Nov 21, 2024
Sep 30, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
In Apache Hadoop versions 3.0.0-alpha2 to 3.0.0, 2.9.0 to 2.9.2, 2.8.0 to 2.8.5, any users can access some servlets without authentication when Kerberos authentication is enabled and SPNEGO through HTTP is not enabled.
1Trendmicro
1Apex One
Jun 17, 2026
Sep 29, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code ex...Show more
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit this vulnerability.Show less
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
1Cpanel
1Cpanel
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
1Ory
1Fosite
Jun 17, 2026
Sep 24, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the uniqueness of the `jti` value is not checked. When using client authentic...Show more
In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the uniqueness of the `jti` value is not checked. When using client authentication method "private_key_jwt", OpenId specification says the following about assertion `jti`: "A unique identifier for the token, which can be used to prevent reuse of the token. These tokens MUST only be used once, unless conditions for reuse were negotiated between the parties". Hydra does not seem to check the uniqueness of this `jti` value. This problem is fixed in version 0.31.0.Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Sep 23, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative...Show more
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The vulnerability is due to improper handling of Lightweight Directory Access Protocol (LDAP) authentication responses from an external authentication server. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to gain administrative access to the web-based management interface of the affected device.Show less
1Cisco
114Sf200 24 Firmware
Sf200 24fp FirmwareSf200 24p Firmware+111 more
Jun 17, 2026
Sep 23, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentica...Show more
A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible from the web UI. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web UI of an affected device. A successful exploit could allow the attacker to access sensitive device information, which includes configuration files.Show less
1Citrix
1Xenmobile Server
Jun 17, 2026
Sep 18, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to...Show more
Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.Show less
1Citrix
1Storefront Server
Jun 17, 2026
Sep 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that serv...Show more
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.Show less
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 16, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard data via improper access control in the user interface.
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 15, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configuration files via improper access control in the user interface.
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 15, 2020
N/A· v4
4.6 MEDIUM· v3
4.1 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected log data via improper access controls in the user interface.
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 15, 2020
N/A· v4
4.6 MEDIUM· v3
4.1 MEDIUM· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected files via improper access controls in the REST interface.
1Mcafee
1Web Gateway
Jun 17, 2026
Sep 15, 2020
N/A· v4
9.0 CRITICAL· v3
7.7 HIGH· v2
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user in...Show more
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user interface.Show less