CWE-287
4,502 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,502)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SY...Show more |
A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames. The vuln...Show more |
1Hp 1Intelligent Management Center Jun 17, 2026 Jun 5, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. |
1Hp 1Intelligent Management Center Jun 17, 2026 Jun 5, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. |
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobi...Show more |
There is an improper authentication vulnerability in some Huawei AP products before version V200R009C00SPC800. Due to the improper implementation of authentication for the serial port, an attacker could exploit this vuln...Show more |
In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing approach for data/backup/DyyyymmddThhmmss.sql filenames. |
1Glpi Dashboard Project 1Glpi Dashboard Jun 17, 2026 Jun 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh. |
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service. |
In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can see a map image without login even if victim enables login-required in setting. |
1Qualcomm 25Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+22 moreNov 21, 2024 May 24, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper authentication in locked memory region can lead to unprivilged access to the memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Indus...Show more |
1Qualcomm 42Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+39 moreNov 21, 2024 May 24, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, S...Show more |
Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authenticate a user. If an attacker has a token allowing them to read the user details of a victim, they c...Show more |
1Schneider Electric 7Net5500 Firmware Net5501 I FirmwareNet5501 Xt Firmware+4 moreJun 17, 2026 May 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts...Show more |
1Schneider Electric 4Modicon M340 Firmware Modicon M580 FirmwareModicon Premium Firmware+1 moreJun 17, 2026 May 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriti...Show more |
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to...Show more |
2Drupal Sensiolabs2Drupal SymfonyJun 17, 2026 May 16, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration an...Show more |
1Ellucian 2Banner Enterprise Identity Services Banner Web TailorJun 17, 2026 May 14, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Tailor 8.8.3, 8.8.4, and 8.9 and Banner Enterprise Identity Services 8.3, 8.3.1, 8.3.2, and 8.4, in co...Show more |
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator)...Show more |
1Cisco 1Elastic Services Controller Jun 17, 2026 May 10, 2019 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API...Show more |