CWE-287
4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,502)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 3Integrated Management Controller Supervisor Ucs DirectorUcs Director Express For Big DataJun 17, 2026 Aug 21, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote att...Show more |
1Cisco 2Ucs Director Ucs Director Express For Big DataJun 17, 2026 Aug 21, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco UCS Director and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actio...Show more |
1Cisco 3Integrated Management Controller Supervisor Ucs DirectorUcs Director Express For Big DataJun 17, 2026 Aug 21, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote att...Show more |
1Forcepoint 1Next Generation Firewall Jun 17, 2026 Aug 20, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vulnerability that potentially allows unauthorized users to bypass passwor...Show more |
2Debian Gonicus2Debian Linux GosaJun 17, 2026 Aug 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is p...Show more |
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Aug 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989. |
PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation of user-mode data properly, successful exploit could result in malicious code exe...Show more |
1Eq 3 2Homematic Ccu2 Firmware Homematic Ccu3 FirmwareJun 17, 2026 Aug 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28. |
The "Security and Privacy" Encryption feature in Mailpile before 1.0.0rc4 does not exclude disabled, revoked, and expired keys. |
1Cisco 1Enterprise Network Function Virtualization Infrastructure Jun 17, 2026 Aug 8, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to bypass authentication and get limited access to the web-bas...Show more |
Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same network, during periods i...Show more |
1Microdigital 3Mdc N2190v Firmware Mdc N4090 FirmwareMdc N4090w FirmwareJun 17, 2026 Aug 6, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An Incorrect Access Control issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5 because any valid cookie can be used to make requests as an admin. |
NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authenticated, which may lead to code execution, denial of service, escalati...Show more |
1Tcl 1Alcatel Linkzone Firmware Jun 17, 2026 Aug 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrat...Show more |
IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed in plain text in the ERP trace file. IBM X-Force ID: 154280. |
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93). |
cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321). |
cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107). |
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104). |