CWE-287
4,511 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,511)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
It is possible to enumerate access card credentials via an unauthenticated network connection to the server in versions of Command Centre v8.20 prior to v8.20.1166(MR3), versions of 8.10 prior to v8.10.1211(MR5), version...Show more |
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project. |
1Bluetooth 1Bluetooth Core Specification Jun 17, 2026 Sep 11, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Devices supporting Bluetooth before 5.1 may allow man-in-the-middle attacks, aka BLURtooth. Cross Transport Key Derivation in Bluetooth Core Specification v4.2 and v5.0 may permit an unauthenticated user to establish a b...Show more |
1Philips 2Patient Information Center Ix Performancebridge Focal PointJun 17, 2026 Sep 11, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a given identity, the software does not prove or insufficiently proves th...Show more |
An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and below. Client-side authentication is used for critical functions such a...Show more |
1Siemens 1Simatic Hmi United Comfort Panels Firmware Jun 17, 2026 Sep 9, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a...Show more |
Authentication Protection Bypass vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows physical local users to bypass the Windows lock screen via triggering certain dete...Show more |
1Qualcomm 28Ipq6018 Firmware Kamorta FirmwareMsm8998 Firmware+25 moreJun 17, 2026 Sep 8, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 u'Improper authentication and signature verification of debug polices in secure boot loader will allow unverified debug policies to be loaded into secure memory and leads to memory corruption' in Snapdragon Auto, Snapdra...Show more |
Tenda AC18 Router through V15.03.05.05_EN and through V15.03.05.19(6318) CN devices could cause a remote code execution due to incorrect authentication handling of vulnerable logincheck() function in /usr/lib/lua/ngx_aut...Show more |
Because of unauthenticated password changes in ForLogic Qualiex v1 and v3, customer and admin permissions and data can be accessed via a simple request. NOTE: as of 2025-10-14, the Supplier's perspective is that this is...Show more |
MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failu...Show more |
1Zohocorp 11Manageengine Ad360 Manageengine Adaudit PlusManageengine Admanager Plus+8 moreJun 17, 2026 Aug 31, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, Recov...Show more |
1Bitdefender 2Endpoint Security Endpoint Security ToolsJun 17, 2026 Aug 30, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An improper authentication vulnerability in Bitdefender Endpoint Security Tools for Windows and Bitdefender Endpoint Security SDK allows an unprivileged local attacker to escalate privileges or tamper with the product's...Show more |
1Scratch Wiki 1Scratch Login Jun 17, 2026 Aug 28, 2020 N/A· v4 10.0 CRITICAL· v3 6.4 MEDIUM· v2 in Scratch Login (MediaWiki extension) before version 1.1, any account can be logged into by using the same username with leading, trailing, or repeated underscore(s), since those are treated as whitespace and trimmed by...Show more |
1Trendmicro 2Deep Security Manager Vulnerability ProtectionJun 17, 2026 Aug 27, 2020 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to...Show more |
1Trendmicro 2Deep Security Manager Vulnerability ProtectionJun 17, 2026 Aug 27, 2020 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass ma...Show more |
1Ibm 1Security Guardium Insights Jun 17, 2026 Aug 27, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 IBM Security Guardium Insights 2.0.1 could allow an attacker to obtain sensitive information or perform unauthorized actions due to improper authenciation mechanisms. IBM X-Force ID: 174403. |
1Cisco 1Connected Mobile Experiences Jun 17, 2026 Aug 26, 2020 N/A· v4 6.7 MEDIUM· v3 3.6 LOW· v2 A vulnerability in the CLI of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to bypass restrictions on the CLI. The vulnerability is due to insuffici...Show more |
1Niscomed 1M1000 Multipara Patient Monitor Firmware Jun 17, 2026 Aug 26, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access t...Show more |
HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1. |