CWE-287
4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,502)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102). |
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101). |
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378). |
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). |
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8...Show more |
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424). |
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process. |
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider. |
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events. |
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user wit...Show more |
1Printeron 1Central Print Services Nov 21, 2024 Jul 29, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level priv...Show more |
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link. |
1Qualcomm 24Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+21 moreNov 21, 2024 Jul 22, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer E...Show more |
Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access. |
1Cisco 1Vision Dynamic Signage Director Jun 17, 2026 Jul 17, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected system. The vulnerability is due to insufficient...Show more |
1Intel 2Ssd Dc S4500 Firmware Ssd Dc S4600 FirmwareNov 21, 2024 Jul 11, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 may allow an unprivileged user to potentially enable escalation of privilege via physical access. |
1Ge 4Aespire 7100 Firmware Aespire 7900 FirmwareAestiva 7100 Firmware+1 moreJun 17, 2026 Jul 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remot...Show more |
1Sonatype 1Nexus Repository Manager Jun 17, 2026 Jul 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials). |
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injec...Show more |
iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the management console and operate the product via unspecified vectors. |