CWE-287
4,492 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,492)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to guess a user password...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.699 build 1001. User interaction is required to exploit this vulnerability. The sp...Show more |
The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token. |
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can misuse these functionalities to perform unauthorized actions, as demon...Show more |
1Aztech 3Adsl Dsl5018en (1t1r) Firmware Dsl705e FirmwareDsl705eu FirmwareNov 21, 2024 Jan 12, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administra...Show more |
1Aztech 3Adsl Dsl5018en (1t1r) Firmware Dsl705e FirmwareDsl705eu FirmwareNov 21, 2024 Jan 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct re...Show more |
An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain instructions during commit, which is configured under the [system scripts...Show more |
1Lenovo 1Enterprise Network Operating System Nov 21, 2024 Jan 10, 2018 N/A· v4 7.0 HIGH· v3 6.2 MEDIUM· v2 In Enterprise Networking Operating System (ENOS) in Lenovo and IBM RackSwitch and BladeCenter products, an authentication bypass known as "HP Backdoor" was discovered during a Lenovo security audit in the serial console,...Show more |
An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to subvert security mechanisms and...Show more |
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak...Show more |
The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, all...Show more |
1Emc 3Avamar Server Integrated Data Protection ApplianceNetworkerNov 21, 2024 Jan 5, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in EMC Avamar Server 7.1.x, 7.2.x, 7.3.x, 7.4.x, 7.5.0; EMC NetWorker Virtual Edition (NVE) 9.0.x, 9.1.x, 9.2.x; and EMC Integrated Data Protection Appliance 2.0. A remote unauthenticated maliciou...Show more |
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address |
2Debian Pysaml2 Project2Debian Linux Pysaml2Nov 21, 2024 Jan 2, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password. |
1Oturia 1Smart Google Code Inserter Nov 21, 2024 Jan 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic paramet...Show more |
2Hawt Redhat2Hawtio Jboss FuseMay 13, 2026 Dec 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter. |
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions...Show more |
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask. |
1Paid To Read Script Project 1Paid To Read Script May 13, 2026 Dec 20, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php uid parameter. |
1Westerndigital 1My Cloud Pr4100 Firmware May 13, 2026 Dec 12, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without a...Show more |