CWE-287
4,504 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,504)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP_AUTH header timestamp value. In HTTP requests, part of the HNAP_AUTH header is the timestamp used t...Show more |
libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocar...Show more |
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c. |
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted. |
1Json Pattern Validator Project 1Json Pattern Validator Jun 17, 2026 Dec 2, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This af...Show more |
Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication. |
1Huawei 2Band 2 Firmware Band 3 FirmwareJun 17, 2026 Nov 29, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the...Show more |
2Debian Ruby Lang2Debian Linux RubyJun 17, 2026 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Nov 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in...Show more |
2Opensuse Redhat4Ansible Backports SleLeap+1 moreJun 17, 2026 Nov 26, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None |
1Cisco 6Webex Event Center Webex Meeting CenterWebex Meetings Online+3 moreJun 17, 2026 Nov 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability in web interface of the Cisco Webex Event Center, Cisco Webex Meeting Center, Cisco Webex Support Center, and Cisco Webex Training Center could allow an unauthenticated, remote attacker to guess account u...Show more |
1Abb 2Plant Connect Power Generation Information ManagerJun 17, 2026 Nov 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract...Show more |
1Broadcom 1Symantec Critical System Protection Jun 17, 2026 Nov 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent e...Show more |
An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute arbitrary commands. |
Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites for a short period of t...Show more |
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication. |
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. |
1Zyxel 9Gs1900 10hp Firmware Gs1900 16 FirmwareGs1900 24 Firmware+6 moreJun 17, 2026 Nov 14, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-...Show more |
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no...Show more |
1Intel 1Baseboard Management Controller Firmware Jun 17, 2026 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Authentication bypass in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via local access...Show more |