← Back
CWE-287

4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Serpico Project
1Serpico
Jun 17, 2026
Jan 15, 2020
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password scre...Show more
An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. An admin can change their password without providing the current password, by using interfaces outside the Change Password screen. Thus, requiring the admin to enter an Old Password value on the Change Password screen does not enhance security. This is problematic in conjunction with XSS.Show less
1Arialsoftware
1Campaign Enterprise
Nov 21, 2024
Jan 10, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.
3Sphider
Sphider PlusSphiderpro
3Sphider
Sphider PlusSphider Pro
Nov 21, 2024
Jan 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
1Browserid Project
1Browserid
Nov 21, 2024
Jan 9, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.
1Plixer
1Scrutinizer Netflow & Sflow Analyzer
Nov 21, 2024
Jan 9, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges vi...Show more
cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.Show less
1Huawei
1Mate 20 Pro Firmware
Jun 17, 2026
Jan 9, 2020
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which cou...Show more
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacker to forge a crafted application as a normal one. Successful exploit could allow the attacker to bypass digital balance function.Show less
1Huawei
1Mate 20 Firmware
Jun 17, 2026
Jan 9, 2020
N/A· v4
6.6 MEDIUM· v3
7.2 HIGH· v2
HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error under certain scenario, successful exploit could allow the attacker who...Show more
HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error under certain scenario, successful exploit could allow the attacker who gains the privilege of guest user to access to the host user's desktop in an instant, without unlocking the screen lock of the host user.Show less
1Atos
14Openscape Desk Phone Ip 35g Eco Firmware
Openscape Desk Phone Ip 35g FirmwareOpenscape Desk Phone Ip 55g Firmware+11 more
Nov 21, 2024
Jan 9, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
3Canonical
DebianMozilla
3Debian Linux
FirefoxUbuntu Linux
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application...Show more
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.Show less
1Broadcom
1Ca Automic Sysload
Jun 17, 2026
Jan 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.
1Givewp
1Givewp
Jun 17, 2026
Jan 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and...Show more
A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and email addresses. Once an API key has been set to any meta key value from the wp_usermeta table, and the token is set to the corresponding MD5 hash of the meta key selected, one can make a request to the restricted endpoints, and thus access sensitive donor data.Show less
1Cisco
4Linksys E4200 Firmware
Linksys Ea2700 FirmwareLinksys Ea3500 Firmware+1 more
Nov 21, 2024
Jan 7, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access
1Schneider Electric
1Clearscada
Jun 17, 2026
Jan 6, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modif...Show more
A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -with initial releases before 1 January 2019- which could cause a low privilege user to delete or modify database, setting or certificate files. Those users must have access to the file system of that operating system to exploit this vulnerability. Affected versions in current support includes ClearSCADA 2017 R3, ClearSCADA 2017 R2, and ClearSCADA 2017.Show less
1Bombba Project
1Bombba
Nov 21, 2024
Dec 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The quaker function of a smart contract implementation for BOMBBA (BOMB), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.
1Ddq Project
1Ddq
Nov 21, 2024
Dec 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The owned function of a smart contract implementation for DDQ, an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.
1Newinteltechmedia Project
1Newinteltechmedia
Nov 21, 2024
Dec 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller'...Show more
The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.Show less
1Cryptbond Network Project
1Cryptbond Network
Nov 21, 2024
Dec 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the calle...Show more
The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Dec 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
1Avtech
1Avn801 Dvr Firmware
Nov 21, 2024
Dec 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AVTECH AVN801 DVR has a security bypass via the administration login captcha
1Hikvision
1Ds 2cd7153 E Firmware
Nov 21, 2024
Dec 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials