CWE-287
4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,502)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffi...Show more |
1Nxp 3Kinetis K8x Firmware Kinetis Kv1x FirmwareKinetis Kv3x FirmwareJun 17, 2026 Sep 24, 2019 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only r...Show more |
1St 6Stm32f4 Firmware Stm32f7 FirmwareStm32h7 Firmware+3 moreJun 17, 2026 Sep 24, 2019 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug probe via the Instruction Tightly Coupled Memory (ITCM) bus. |
1Supermicro 321A1sa2 2750f Firmware A1sai 2550f FirmwareA1sai 2750f Firmware+318 moreJun 17, 2026 Sep 21, 2019 N/A· v4 10.0 CRITICAL· v3 5.0 MEDIUM· v2 On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devic...Show more |
1Schneider Electric 2Spacelynk Firmware Wiser For Knx FirmwareJun 17, 2026 Sep 17, 2019 N/A· v4 8.3 HIGH· v3 6.8 MEDIUM· v2 A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known as homeLYnk), which could cause loss of control when an attacker bypas...Show more |
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data. |
1Tripplite 1Pdumh15at Firmware Jun 17, 2026 Sep 12, 2019 N/A· v4 9.1 CRITICAL· v3 8.5 HIGH· v2 Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ directory, as demonstrated by changing the manager or admin password, or shutting off power to an outlet....Show more |
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence. |
1Dlink 3Dir 868l Firmware Dir 885l FirmwareDir 895l FirmwareJun 17, 2026 Sep 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to folder_view.php or catego...Show more |
An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and 12.0.4. |
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is...Show more |
In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application. |
Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network. |
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page. |
Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may allow an attacker to remotely execute arbitrary code. |
2Androvideo Geovision3Gv Vd8700 Firmware Gv Vr360 FirmwareVd 1 FirmwareJun 17, 2026 Aug 29, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker can export system configuration which is not encrypted to get the administrator’s account and password...Show more |
A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is...Show more |
1Elearningfreak 1Insert Or Embed Articulate Content Jun 17, 2026 Aug 27, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. |
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserver user when providing wrong credentials when all of the following cond...Show more |
1Wpsupportplus 1Wp Support Plus Responsive Ticket System Nov 21, 2024 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. |