← Back
CWE-287

4,488 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,488)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
2Vcm5010 Firmware
Vcm5020 Firmware
May 13, 2026
Aug 28, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operati...Show more
Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operation as another user via a crafted message, aka "Horizontal Privilege Escalation Vulnerability."Show less
1Ldap / Sso Authentication Project
1Ldap / Sso Authentication
May 13, 2026
Aug 28, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
1Osisoft
1Pi Data Archive
May 13, 2026
Aug 25, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw that could allow a malicious user to auth...Show more
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw that could allow a malicious user to authenticate with a server and then cause PI Network Manager to behave in an undefined manner.Show less
1Osisoft
1Pi Data Archive
May 13, 2026
Aug 25, 2017
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws with the potential to expose change records in the clear and allow a ma...Show more
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws with the potential to expose change records in the clear and allow a malicious party to spoof a server within a collective.Show less
1Apple
1Pykerberos
May 13, 2026
Aug 25, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by...Show more
The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows remote attackers to cause a denial of service (bad response), or have other unspecified impact by performing a man-in-the-middle attack.Show less
1D Link
2Dns 320l Firmware
Dns 327l Firmware
May 13, 2026
Aug 25, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to...Show more
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to an arbitrary Facebook profile via a target album_id and access_token.Show less
1D Link
1Dnr 326 Firmware
May 13, 2026
Aug 25, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username cookie parameter to an arbitrary string.
1D Link
7Dnr 326 Firmware
Dns 320b FirmwareDns 320l Firmware+4 more
May 13, 2026
Aug 25, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and lo...Show more
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administrator permissions by passing the cgi_set_wto command in the cmd parameter, and setting the spawned session's cookie to username=admin.Show less
1Lxdm Project
1Lxdm
May 13, 2026
Aug 24, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.
1Apache
1Pony Mail
May 13, 2026
Aug 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
1Haproxy
1Haproxy
May 13, 2026
Aug 22, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.
1Powerdns
1Dnsdist
May 13, 2026
Aug 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
1Microfocus
3Enterprise Developer
Enterprise ServerEnterprise Server Monitor And Control
May 13, 2026
Aug 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Updat...Show more
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter configuration information and alter the state of the running product (CWE-275).Show less
1Kguardsecurity
2Kg Sha104 Firmware
Kg Sha108 Firmware
May 13, 2026
Aug 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server.
1Cisco
1Policy Suite
May 13, 2026
Aug 17, 2017
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability in the management of shell user accounts for Cisco Policy Suite (CPS) Software for CPS appliances could allow an authenticated, local attacker to gain elevated privileges on an affected system. The affect...Show more
A vulnerability in the management of shell user accounts for Cisco Policy Suite (CPS) Software for CPS appliances could allow an authenticated, local attacker to gain elevated privileges on an affected system. The affected privilege level is not at the root level. The vulnerability is due to incorrect role-based access control (RBAC) for shell user accounts. An attacker could exploit this vulnerability by authenticating to an affected appliance and providing crafted user input via the CLI. A successful exploit could allow the attacker to acquire a higher privilege level than should have been granted. To exploit this vulnerability, the attacker must log in to the appliance with valid credentials. Cisco Bug IDs: CSCve37724. Known Affected Releases: 9.0.0, 9.1.0, 10.0.0, 11.0.0, 12.0.0.Show less
2Debian
Postgresql
2Debian Linux
Postgresql
May 13, 2026
Aug 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
2Fedoraproject
Ganglia
2Fedora
Ganglia Web
May 13, 2026
Aug 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
1Blackberry
1Workspaces
May 13, 2026
Aug 9, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's...Show more
An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server.Show less
1Apache
1Cxf
May 13, 2026
Aug 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The WS-SP UsernameToken policy in Apache CXF 2.4.5 and 2.5.1 allows remote attackers to bypass authentication by sending an empty UsernameToken as part of a SOAP request.
1Synology
1Photo Station
May 13, 2026
Aug 8, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.