CWE-287
4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,504)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password scre...Show more |
1Arialsoftware 1Campaign Enterprise Nov 21, 2024 Jan 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization. |
3Sphider Sphider PlusSphiderpro3Sphider Sphider PlusSphider ProNov 21, 2024 Jan 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass |
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier. |
1Plixer 1Scrutinizer Netflow & Sflow Analyzer Nov 21, 2024 Jan 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges vi...Show more |
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which cou...Show more |
HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error under certain scenario, successful exploit could allow the attacker who...Show more |
1Atos 14Openscape Desk Phone Ip 35g Eco Firmware Openscape Desk Phone Ip 35g FirmwareOpenscape Desk Phone Ip 55g Firmware+11 moreNov 21, 2024 Jan 9, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface |
3Canonical DebianMozilla3Debian Linux FirefoxUbuntu LinuxJun 17, 2026 Jan 8, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application...Show more |
1Broadcom 1Ca Automic Sysload Jun 17, 2026 Jan 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands. |
A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and...Show more |
1Cisco 4Linksys E4200 Firmware Linksys Ea2700 FirmwareLinksys Ea3500 Firmware+1 moreNov 21, 2024 Jan 7, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access |
A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modif...Show more |
The quaker function of a smart contract implementation for BOMBBA (BOMB), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity. |
The owned function of a smart contract implementation for DDQ, an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity. |
1Newinteltechmedia Project 1Newinteltechmedia Nov 21, 2024 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller'...Show more |
1Cryptbond Network Project 1Cryptbond Network Nov 21, 2024 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the calle...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control. |
AVTECH AVN801 DVR has a security bypass via the administration login captcha |
1Hikvision 1Ds 2cd7153 E Firmware Nov 21, 2024 Dec 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials |