← Back
CWE-287

4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,504)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Magdevgroup
1Magnolia Cms
Nov 21, 2024
Dec 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities
1Belkin
1N900 Firmware
Nov 21, 2024
Dec 26, 2019
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
1Belkin
1F5d8236 4 Firmware
Nov 21, 2024
Dec 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.
1Fedoraproject
1Sssd
Nov 21, 2024
Dec 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux...Show more
A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.Show less
1Dlink
1Dir 601 Firmware
Jun 17, 2026
Dec 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life prod...Show more
D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.Show less
1Icegram
1Email Subscribers & Newsletters
Jun 17, 2026
Dec 26, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-po...Show more
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.Show less
5Canonical
DebianLinux+2 more
168300 Firmware
8700 FirmwareA400 Firmware+13 more
Jun 17, 2026
Dec 23, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the require...Show more
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has completed. This could lead to different denial-of-service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby APs of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 18, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions...Show more
A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.Show less
1Apple
2Ipados
Iphone Os
Jun 17, 2026
Dec 18, 2019
N/A· v4
5.7 MEDIUM· v3
2.9 LOW· v2
An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during...Show more
An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.Show less
1Apple
1Iphone Os
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.
1Apple
2Iphone Os
Tvos
Jun 17, 2026
Dec 18, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.
1Apple
1Mac Os X
Jun 17, 2026
Dec 18, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An authentication issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5. A user may be unexpectedly logged in to another user’s account.
1Apple
1Mac Os X
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A lock handling issue was addressed with improved lock handling. This issue is fixed in macOS Mojave 10.14.4. A Mac may not lock when disconnecting from an external monitor.
2Debian
Requests Kerberos Project
2Debian Linux
Requests Kerberos
Nov 21, 2024
Dec 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
python-requests-Kerberos through 0.5 does not handle mutual authentication
1Huawei
6Enjoy 8 Plus Firmware
Honor 8x FirmwareHonor 9 Lite Firmware+3 more
Jun 17, 2026
Dec 14, 2019
N/A· v4
3.5 LOW· v3
3.6 LOW· v2
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit cou...Show more
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.Show less
1Huawei
1E5572 855 Firmware
Jun 17, 2026
Dec 13, 2019
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does not perform a sufficient authentication when doing certain operations, successful exploit could allo...Show more
E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does not perform a sufficient authentication when doing certain operations, successful exploit could allow an attacker to cause the device to reboot after launch a man in the middle attack.Show less
1Suphp
1Suphp
Nov 21, 2024
Dec 13, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution
1W1.fi
1Hostapd
Jun 17, 2026
Dec 12, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This coul...Show more
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby Aps of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.Show less
1Siemens
2Sinvr 3 Central Control Server
Sinvr 3 Video Server
Jun 17, 2026
Dec 12, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) contains an authentication bypass vulnerability. A re...Show more
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) contains an authentication bypass vulnerability. A remote attacker with network access to the CCS server could exploit this vulnerability to read data from the EDIR directory (for example, the list of all configured stations).Show less
1Siemens
2Sinvr 3 Central Control Server
Sinvr 3 Video Server
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provi...Show more
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. A remote attacker with network access to the CCS server could exploit this vulnerability to read the CCS users database, including the passwords of all users in obfuscated cleartext.Show less