← Back
CWE-287

4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,502)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.5 MEDIUM· v3
7.5 HIGH· v2
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
1Redhat
1Openshift
Jun 17, 2026
Aug 1, 2019
N/A· v4
5.4 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8...Show more
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
cPanel before 74.0.0 allows file modification in the context of the root account because of incorrect HTTP authentication (SEC-424).
1Nextcloud
1Nextcloud
Jun 17, 2026
Jul 30, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
1Nextcloud
1Nextcloud
Jun 17, 2026
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Jul 30, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
1Suse
1Rancher
Jun 17, 2026
Jul 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user wit...Show more
An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher administrator may choose to delete this default admin user. If Rancher is restarted, the default admin user will be recreated with the well-known default password. An attacker could exploit this by logging in with the default admin credentials. This can be mitigated by deactivating the default admin user rather than completing deleting them.Show less
1Printeron
1Central Print Services
Nov 21, 2024
Jul 29, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level priv...Show more
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform other attacks.Show less
1Discourse
1Discourse
Jun 17, 2026
Jul 29, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
1Qualcomm
24Mdm9206 Firmware
Mdm9607 FirmwareMdm9650 Firmware+21 more
Nov 21, 2024
Jul 22, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer E...Show more
Debug policy with invalid signature can be loaded when the debug policy functionality is disabled by using the parallel image loading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, SD 410/12, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SXR1130Show less
1Mongodb
1Mongodb
Nov 21, 2024
Jul 19, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.
1Cisco
1Vision Dynamic Signage Director
Jun 17, 2026
Jul 17, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected system. The vulnerability is due to insufficient...Show more
A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on the affected system. The REST API is enabled by default and cannot be disabled.Show less
1Intel
2Ssd Dc S4500 Firmware
Ssd Dc S4600 Firmware
Nov 21, 2024
Jul 11, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 may allow an unprivileged user to potentially enable escalation of privilege via physical access.
1Ge
4Aespire 7100 Firmware
Aespire 7900 FirmwareAestiva 7100 Firmware+1 more
Jun 17, 2026
Jul 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remot...Show more
In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.Show less
1Sonatype
1Nexus Repository Manager
Jun 17, 2026
Jul 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
1Dlink
1Central Wifimanager
Jun 17, 2026
Jul 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injec...Show more
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.Show less
1Idoors
1Idoors Reader
Jun 17, 2026
Jul 5, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the management console and operate the product via unspecified vectors.