CWE-287
4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,504)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sonicwall 4Analyzer Global Management SystemUniversal Management Appliance+1 moreNov 21, 2024 Feb 11, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1...Show more |
1Sonicwall 4Analyzer Global Management SystemUniversal Management Appliance+1 moreNov 21, 2024 Feb 11, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and...Show more |
1Claris 2Filemaker Pro Filemaker Pro AdvancedNov 21, 2024 Feb 11, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges. |
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physic...Show more |
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used). |
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers. |
D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability. |
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging." |
1Netgear 2Wgr614v7 Firmware Wgr614v9 FirmwareNov 21, 2024 Feb 6, 2020 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002. |
1Wptimecapsule 1Wp Time Capsule Jun 17, 2026 Feb 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts. |
1Cisco 1Linksys E4200 Firmware Nov 21, 2024 Feb 5, 2020 N/A· v4 9.8 CRITICAL· v3 4.3 MEDIUM· v2 Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access. |
IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. |
Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature. |
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login. |
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past. |
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters |
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. |
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password. |
1Arubanetworks 3Airwave Aruba InstantArubaosNov 21, 2024 Jan 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive informatio...Show more |
Evernote prior to 5.5.1 has insecure password change |