← Back
CWE-287

4,489 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,489)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Psftp
1Psftpd
May 13, 2026
Nov 15, 2017
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however,...Show more
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data. Cleartext is used for a user password.Show less
1Dahuasecurity
22Nvr5208 4ks2 Firmware
Nvr5208 8p 4ks2 FirmwareNvr5216 16p 4ks2 Firmware+19 more
May 13, 2026
Nov 13, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additi...Show more
Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.Show less
1Joomla
1Joomla
May 13, 2026
Nov 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.
1Userproplugin
1Userpro
May 13, 2026
Nov 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log pa...Show more
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.Show less
1Meetcircle
1Circle With Disney Firmware
May 13, 2026
Nov 7, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token can bypass the authentication routine of the Apid binary, causing the de...Show more
An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token can bypass the authentication routine of the Apid binary, causing the device to grant unintended administrative access. An attacker needs network connectivity to the device to trigger this vulnerability.Show less
1Meetcircle
1Circle With Disney Firmware
May 13, 2026
Nov 7, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets can cause a valid authentication token to be returned to the attacker r...Show more
An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets can cause a valid authentication token to be returned to the attacker resulting in authentication bypass. An attacker can send a series of packets to trigger this vulnerability.Show less
1Mahara
1Mahara
May 13, 2026
Nov 3, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their ins...Show more
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspended.Show less
1Cisco
3Aironet 1800 Firmware
Aironet 2800 FirmwareAironet 3800 Firmware
May 13, 2026
Nov 2, 2017
N/A· v4
7.5 HIGH· v3
5.4 MEDIUM· v2
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an unauthent...Show more
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an unauthenticated, adjacent attacker to bypass authentication and connect to an affected device. The vulnerability exists because the affected device uses an incorrect default configuration setting of fail open when running in standalone mode. An attacker could exploit this vulnerability by attempting to connect to an affected device. A successful exploit could allow the attacker to bypass authentication and connect to the affected device. This vulnerability affects Cisco Aironet 1800, 2800, and 3800 Series Access Points that are running a vulnerable software release and use WLAN configuration settings that include FlexConnect local switching and central authentication with MAC filtering. Cisco Bug IDs: CSCvd46314.Show less
1Osstech
1Openam
May 13, 2026
Nov 2, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configu...Show more
OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configured as SAML 2.0IdP, and switches authentication methods based on AuthnContext requests sent from the service provider.Show less
1Ibm
1Bigfix Platform
May 13, 2026
Oct 26, 2017
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 123862.
1Redhat
1Keycloak
May 13, 2026
Oct 26, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker...Show more
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker on an already compromised resource could use this flaw to grant himself continued permissions and possibly conduct further attacks.Show less
1Siemens
4Apogee Pxc Firmware
Apogee Pxc Modular FirmwareTalon Tc Compact Firmware+1 more
Jun 2, 2026
Oct 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass t...Show more
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.Show less
1Apache
1Nifi
May 13, 2026
Oct 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.
1Cisco
1Cloud Services Platform 2100
May 13, 2026
Oct 19, 2017
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciously with the services or virtual machines (VMs) operating remotely on a...Show more
A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciously with the services or virtual machines (VMs) operating remotely on an affected CSP device. The vulnerability is due to weaknesses in the generation of certain authentication mechanisms in the URL of the web console. An attacker could exploit this vulnerability by browsing to one of the hosted VMs' URLs in Cisco CSP and viewing specific patterns that control the web application's mechanisms for authentication control. An exploit could allow the attacker to access a specific VM on the CSP, which causes a complete loss of the system's confidentiality, integrity, and availability. This vulnerability affects Cisco Cloud Services Platform (CSP) 2100 running software release 2.1.0, 2.1.1, 2.1.2, 2.2.0, 2.2.1, or 2.2.2. Cisco Bug IDs: CSCve64690.Show less
1Interspire
1Email Marketer
May 13, 2026
Oct 18, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using...Show more
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a specially crafted value.Show less
1Envitech
1Envidas Ultimate
May 13, 2026
Oct 17, 2017
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settin...Show more
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely.Show less
1Sap
1Host Agent
May 13, 2026
Oct 16, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
1Sap
1Point Of Sale Xpress Server
May 13, 2026
Oct 16, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.
1Sap
1Point Of Sale Xpress Server
May 13, 2026
Oct 16, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064.
1Juniper
1Junos Space
May 13, 2026
Oct 13, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes...Show more
Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes. Affected releases are Juniper Networks Junos Space all versions prior to 17.1R1.Show less