← Back
CWE-287

4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
4Analyzer
Global Management SystemUniversal Management Appliance+1 more
Nov 21, 2024
Feb 11, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1...Show more
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA interface (/appliance/), which could let a remote malicious user obtain access to the root account.Show less
1Sonicwall
4Analyzer
Global Management SystemUniversal Management Appliance+1 more
Nov 21, 2024
Feb 11, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and...Show more
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which could let a remote malicious user obtain administrative access.Show less
1Claris
2Filemaker Pro
Filemaker Pro Advanced
Nov 21, 2024
Feb 11, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.
1Samsung
1Knox
Jun 17, 2026
Feb 10, 2020
N/A· v4
4.3 MEDIUM· v3
2.1 LOW· v2
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physic...Show more
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this vulnerability. The specific flaws exists within the the handling of the lock screen for Secure Folder. The issue results from the lack of proper validation that a user has correctly authenticated. An attacker can leverage this vulnerability to disclose the contents of the secure container. Was ZDI-CAN-7381.Show less
1Mfscripts
1Yetishare
Jun 17, 2026
Feb 10, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).
1Linuxcontainers
1Lxc
Nov 21, 2024
Feb 10, 2020
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
1Dlink
1Dir865l Firmware
Nov 21, 2024
Feb 7, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
D-Link DIR865L v1.03 suffers from an "Unauthenticated Hardware Linking" vulnerability.
1Belkin
1N300 Firmware
Nov 21, 2024
Feb 7, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."
1Netgear
2Wgr614v7 Firmware
Wgr614v9 Firmware
Nov 21, 2024
Feb 6, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002.
1Wptimecapsule
1Wp Time Capsule
Jun 17, 2026
Feb 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.
1Cisco
1Linksys E4200 Firmware
Nov 21, 2024
Feb 5, 2020
N/A· v4
9.8 CRITICAL· v3
4.3 MEDIUM· v2
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.
1Ibm
1Workflow
Nov 21, 2024
Feb 5, 2020
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
IBM Workflow for Bluemix does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
1Nextcloud
1Talk
Jun 17, 2026
Feb 4, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked them to another shared item via the projects feature.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Feb 4, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
1Nextcloud
1Nextcloud
Jun 17, 2026
Feb 4, 2020
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past.
1Dlink
1Dir 100 Firmware
Nov 21, 2024
Feb 4, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
1Eginnovations
1Eg Manager
Jun 17, 2026
Feb 3, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.
1Phpabook Project
1Phpabook
Jun 17, 2026
Feb 3, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.
1Arubanetworks
3Airwave
Aruba InstantArubaos
Nov 21, 2024
Jan 31, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive informatio...Show more
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672Show less
1Evernote
1Evernote
Nov 21, 2024
Jan 31, 2020
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
Evernote prior to 5.5.1 has insecure password change