← Back
CWE-287

4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Logmein
1Lastpass
Nov 21, 2024
Jan 31, 2020
N/A· v4
6.1 MEDIUM· v3
6.6 MEDIUM· v2
LastPass prior to 2.5.1 allows secure wipe bypass.
1Evernote
1Evernote
Nov 21, 2024
Jan 31, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Evernote before 5.5.1 has insecure PIN storage
1Apereo
1Opencast
Jun 17, 2026
Jan 30, 2020
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked...Show more
In Opencast before 7.6 and 8.1, using a remember-me cookie with an arbitrary username can cause Opencast to assume proper authentication for that user even if the remember-me cookie was incorrect given that the attacked endpoint also allows anonymous access. This way, an attacker can, for example, fake a remember-me token, assume the identity of the global system administrator and request non-public content from the search service without ever providing any proper authentication. This problem is fixed in Opencast 7.6 and Opencast 8.1Show less
1Netgear
1Wnr1000 Firmware
Nov 21, 2024
Jan 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
1Netgear
1Wnr1000 Firmware
Nov 21, 2024
Jan 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
1Vtiger
1Vtiger Crm
Nov 21, 2024
Jan 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
1Zavio
2F3105 Firmware
F312a Firmware
Nov 21, 2024
Jan 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stre...Show more
A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream.Show less
1Netgear
1Wndr4700 Firmware
Nov 21, 2024
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
1Dlink
2Dcs 2102 Firmware
Dcs 2121 Firmware
Nov 21, 2024
Jan 28, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-2121 1.06_FR, 1.06, and 1.05_RU, DCS-2102 1.06_FR. 1.06, and...Show more
An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-2121 1.06_FR, 1.06, and 1.05_RU, DCS-2102 1.06_FR. 1.06, and 1.05_RU, which could let a malicious user obtain sensitive information.Show less
1Micasaverde
1Veralite Firmware
Nov 21, 2024
Jan 28, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote a...Show more
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbitrary Lua code via a RunLua action in a request to port_49451/upnp/control/hag.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeov...Show more
Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.Show less
1Totolink
8A3002ru Firmware
A702r FirmwareN100re Firmware+5 more
Jun 17, 2026
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not neede...Show more
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined valid credentials. The attacker can perform router actions via HTTP requests with Basic Authentication.) This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.Show less
1Portable Phpmyadmin Project
1Portable Phpmyadmin
Nov 21, 2024
Jan 27, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability
1Django User Sessions Project
1Django User Sessions
Jun 17, 2026
Jan 24, 2020
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself...Show more
In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS vulnerability, the session key could be extracted by the attacker and a session takeover could happen.Show less
1Vivotek
1Pt7135 Firmware
Nov 21, 2024
Jan 24, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554.
1Lorextechnology
2Lnc104 Firmware
Lnc116 Firmware
Nov 21, 2024
Jan 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
1Huawei
1Honor V30 Firmware
Jun 17, 2026
Jan 21, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its...Show more
Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its interface. An attacker could trick the user into installing a malicious application. Successful exploit could allow unauthorized actions leading to information disclosure.Show less
1Huawei
1Mate 20 Firmware
Jun 17, 2026
Jan 21, 2020
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to exploit this vulnera...Show more
HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to exploit this vulnerability. Successful exploitation may cause information leak and compromise the availability of the smart phones.Affected product versions include: HUAWEI Mate 20 versions Versions earlier than 10.0.0.175(C00E70R3P8)Show less
1Amcrest
1Web Server
Jun 17, 2026
Jan 18, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in...Show more
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (ability to see every option but not modify them).Show less
1Simplisafe
1Ss3 Firmware
Jun 17, 2026
Jan 16, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.0-1.3 allows a local, unauthenticated attacker to pair a rogue keypad to an armed system.