CWE-287
4,489 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,489)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however,...Show more |
1Dahuasecurity 22Nvr5208 4ks2 Firmware Nvr5208 8p 4ks2 FirmwareNvr5216 16p 4ks2 Firmware+19 moreMay 13, 2026 Nov 13, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additi...Show more |
In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method. |
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log pa...Show more |
1Meetcircle 1Circle With Disney Firmware May 13, 2026 Nov 7, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token can bypass the authentication routine of the Apid binary, causing the de...Show more |
1Meetcircle 1Circle With Disney Firmware May 13, 2026 Nov 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets can cause a valid authentication token to be returned to the attacker r...Show more |
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their ins...Show more |
1Cisco 3Aironet 1800 Firmware Aironet 2800 FirmwareAironet 3800 FirmwareMay 13, 2026 Nov 2, 2017 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an unauthent...Show more |
OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configu...Show more |
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 123862. |
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permitting indefinite usage in the case of permission revocation. An attacker...Show more |
1Siemens 4Apogee Pxc Firmware Apogee Pxc Modular FirmwareTalon Tc Compact Firmware+1 moreJun 2, 2026 Oct 23, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass t...Show more |
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user. |
1Cisco 1Cloud Services Platform 2100 May 13, 2026 Oct 19, 2017 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciously with the services or virtual machines (VMs) operating remotely on a...Show more |
1Interspire 1Email Marketer May 13, 2026 Oct 18, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using...Show more |
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settin...Show more |
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993. |
1Sap 1Point Of Sale Xpress Server May 13, 2026 Oct 16, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064. |
1Sap 1Point Of Sale Xpress Server May 13, 2026 Oct 16, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064. |
Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to intercept, inject or disrupt Junos Space cluster operations between two nodes...Show more |