CWE-287
4,501 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,501)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryp...Show more |
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cry...Show more |
1Sap 1Netweaver Process Integration Jun 17, 2026 Apr 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; can be accessed without user authentication, which might expose internal data like relea...Show more |
In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dynamic port forwarding" (SOCKS proxy) functionalities. Remote attackers without credentials can exploi...Show more |
1Tibco 1Activematrix Businessworks Jun 17, 2026 Apr 9, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even whe...Show more |
application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change. |
1Hanwhasecurity 1Srn 4000 Firmware Nov 21, 2024 Apr 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges...Show more |
Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and sub-domains. The vulnerability means that passwords saved for example.com will be recommended for us...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Apr 4, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an a...Show more |
Detcon Sitewatch Gateway, all versions without cellular, an attacker can edit settings on the device using a specially crafted URL. |
13m 1Detcon Sitewatch Gateway Nov 21, 2024 Apr 2, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessible without authentication. |
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the Networker Client execution service (nsrexecd) when oldauth authentication method is used. An unauthenticated re...Show more |
An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and execute administrative...Show more |
1Grandstream 1Gxv3611ir Hd Firmware Jun 17, 2026 Mar 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password. |
Abine Blur 7.8.2431 allows remote attackers to conduct "Second-Factor Auth Bypass" attacks by using the "Perform a right-click operation to access a forgotten dev menu to insert user passwords that otherwise would requir...Show more |
The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can...Show more |
A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the...Show more |
A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could allow an unauthenticated, adjacent attacker to access the network prior to authentication. The vulnerability is due to h...Show more |
When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed d...Show more |
4Canonical FedoraprojectMod Auth Mellon Project+1 more10Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Mar 26, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), a...Show more |