CWE-287
4,496 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,496)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Circontrol 1Circarlife Firmware Nov 21, 2024 Nov 2, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page. |
1Rainmachine 2Mini 8 Firmware Touch Hd 12 FirmwareJun 17, 2026 Nov 1, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the devi...Show more |
The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2nd generation) uses the administrator's password hash to generate a 6-digit temporary passcode that...Show more |
MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late. |
2Redhat Samba8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+5 moreNov 21, 2024 Oct 31, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticke...Show more |
1Nextcloud 1Nextcloud Server Nov 21, 2024 Oct 30, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares. |
1Nextcloud 1Nextcloud Server Nov 21, 2024 Oct 30, 2018 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load. |
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password. |
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php. |
1Sagaradio 1Saga1 L8b Firmware Nov 21, 2024 Oct 24, 2018 N/A· v4 6.9 MEDIUM· v3 6.9 MEDIUM· v2 SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may able to reprogram it. |
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi). |
* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the...Show more |
1Sv3c 1H.264 Poe Ip Camera Firmware Nov 21, 2024 Oct 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) is affected by an improper authentication vulnerability that allows requests to be made to back-end CGI scripts without a va...Show more |
1Sv3c 1H.264 Poe Ip Camera Firmware Nov 21, 2024 Oct 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrato...Show more |
1Ibm 2Flashsystem 840 Firmware Flashsystem 900 FirmwareNov 21, 2024 Oct 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 IBM FlashSystem 900 product GUI allows a specially crafted attack to bypass the authentication requirements of the system, resulting in the ability to remotely change the superuser password. This can be used by an attack...Show more |
Huawei Mate 10 pro smartphones with the versions before BLA-AL00B 8.1.0.326(C00) have an improper authentication vulnerability. App Lock is a function to prevent unauthorized use of apps on smartphones, an attacker could...Show more |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 17, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) prior to iMC PLAT 7.3 E0605P04. |
6Canonical DebianLibssh+3 more9Debian Linux Enterprise LinuxLibssh+6 moreNov 21, 2024 Oct 17, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access. |
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the serve...Show more |
1Teltonika 3Rut900 Firmware Rut950 FirmwareRut955 FirmwareNov 21, 2024 Oct 15, 2018 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root priv...Show more |