CWE-287
4,488 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,488)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An Improper Authentication issue was discovered in JanTek JTC-200, all versions. The improper authentication could provide an undocumented BusyBox Linux shell accessible over the TELNET service without any authentication...Show more |
1Hp 1Intelligent Management Center Plat May 13, 2026 Oct 11, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI. |
1Lavalink 1Ether Serial Link Firmware May 13, 2026 Oct 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, whi...Show more |
InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Manager to reach a file. |
1Ibm 1Tivoli Storage Manager May 13, 2026 Oct 5, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a brute force attack due to disclosing too much information during authentication. An attacker could gain...Show more |
1Ctekproducts 2Skyrouter Z4200 Firmware Skyrouter Z4400 FirmwareMay 13, 2026 Oct 5, 2017 N/A· v4 9.4 CRITICAL· v3 7.5 HIGH· v2 An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able t...Show more |
1Spidercontrol 1Ininet Webserver May 13, 2026 Oct 5, 2017 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not properly authenticate users, which may allow a malicious attacker to access s...Show more |
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. It did no...Show more |
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. Its SCM c...Show more |
1Sentinel 1Sentinel Ldk Rte Firmware May 13, 2026 Oct 4, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55. |
1Hp 1Bsm Platform Application Performance Management System Health May 13, 2026 Sep 30, 2017 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet directory traversal. |
1Hp 1Bsm Platform Application Performance Management System Health May 13, 2026 Sep 30, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to bypass authentication. |
A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, remote attacker using an x tunnel router to bypass authentication checks...Show more |
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affe...Show more |
1Saadamin 1Simple Student Result May 13, 2026 Sep 27, 2017 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing...Show more |
When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be by...Show more |
1Citrix 2Application Delivery Controller Firmware Netscaler Gateway FirmwareMay 13, 2026 Sep 26, 2017 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010...Show more |
1Denyall 2I Suite Web Application FirewallMay 13, 2026 Sep 22, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservices/download/index.php, and then reading the iToken field in the reply. T...Show more |
1Trendmicro 1Mobile Security May 13, 2026 Sep 22, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part of the console using a blank password. |
2Dlink Trendnet15Dir 626l Firmware Dir 636l FirmwareDir 651 Firmware+12 moreApr 21, 2026 Sep 21, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. |