CWE-287
4,495 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,495)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tecrail 1Responsive Filemanager Nov 21, 2024 Oct 10, 2018 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files. |
3Debian StarwindsoftwareTinc Vpn3Debian Linux Starwind Virtual SanTincNov 21, 2024 Oct 10, 2018 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1. |
2Starwindsoftware Tinc Vpn2Starwind Virtual San TincNov 21, 2024 Oct 10, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation. |
An issue was discovered in Descor Infocad FM before 3.1.0.0. An unauthenticated web service allows the retrieval of files on the web server and on reachable SMB servers. |
Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interface just by using "admin:" as the name of a cookie. |
An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without authentication when the system is initially...Show more |
If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. RSH service is disabled by default on Junos. There is no documented...Show more |
An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty. The affected SSHD configur...Show more |
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFa...Show more |
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In oth...Show more |
1D Link 3Dir 809 A1 Firmware Dir 809 A2 FirmwareDir 809 Guestzone FirmwareNov 21, 2024 Oct 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechanisms to download the configuration file. |
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php. |
A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. T...Show more |
A vulnerability in the Cisco Umbrella API could allow an authenticated, remote attacker to view and modify data across their organization and other organizations. The vulnerability is due to insufficient authentication c...Show more |
1Icecoldapps 1Servers Ultimate Nov 21, 2024 Oct 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Ice Cold Apps Servers Ultimate 6.0.2(12) does not require authentication for TELNET, SSH, or FTP, which allows remote attackers to execute arbitrary code by uploading PHP scripts. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Oct 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock |
1Suse 1Subscription Management Tool Nov 21, 2024 Oct 4, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A improper authentication using the HOST header in SUSE Linux SMT allows remote attackers to spoof a sibling server. Affected releases are SUSE Linux SMT: versions prior to 3.0.37. |
1Mcafee 1Data Loss Prevention Endpoint Jun 17, 2026 Oct 3, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditio...Show more |
Entes EMG12 versions 2.57 and prior The application uses a web interface where it is possible for an attacker to bypass authentication with a specially crafted URL. This could allow for remote code execution. |
On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, which allows remote attackers to execute arbitrary code. |