← Back
CWE-287

4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,464)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cisco
1Ios
May 6, 2026
Apr 23, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bu...Show more
The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.Show less
1Cubecart
1Cubecart
May 6, 2026
Apr 22, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
1Mediawiki
1Mediawiki
May 6, 2026
Apr 20, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which ma...Show more
includes/specials/SpecialChangePassword.php in MediaWiki before 1.19.14, 1.20.x and 1.21.x before 1.21.8, and 1.22.x before 1.22.5 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account, as demonstrated by tracking the victim's activity, related to a "login CSRF" issue.Show less
2Fedoraproject
Mozilla
2Bugzilla
Fedora
May 6, 2026
Apr 20, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtai...Show more
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related to a "login CSRF" issue.Show less
1Cybozu
1Remote Service Manager
May 6, 2026
Apr 19, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors.
1Strongswan
1Strongswan
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.
1Openstack
1Keystone
May 6, 2026
Apr 15, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication met...Show more
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."Show less
2Debian
Haxx
3Curl
Debian LinuxLibcurl
May 6, 2026
Apr 15, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context...Show more
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.Show less
1Amtelco
1Misecuremessages
May 6, 2026
Apr 15, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Andr...Show more
Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Android application.Show less
1Zyxel
2N300 Netusb Nbg 419n
N300 Netusb Nbg 419n Firmware
May 6, 2026
Apr 15, 2014
N/A· v4
N/A· v3
6.1 MEDIUM· v2
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to bypass authentication by using %2F sequences in place of / (slash) characters.
1Ontariosystems
4Artiva Architect
Artiva HealthcareArtiva Rm+1 more
May 6, 2026
Apr 15, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option is enabled, allows r...Show more
The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option is enabled, allows remote attackers to login to arbitrary domain accounts by using the corresponding username on a Windows client machine.Show less
1Sap
1Software Deployment Manager
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors related to failed authentications.
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows rem...Show more
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 before 8.6(1.13), 9.0 before 9.0(3.8), and 9.1 before 9.1(3.2) allows remote attackers to bypass authentication via (1) a crafted cookie value within modified HTTP POST data or (2) a crafted URL, aka Bug ID CSCua85555.Show less
1Wordpress
1Wordpress
May 6, 2026
Apr 10, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote atta...Show more
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.Show less
1Emc
1Vplex Geosynchrony
May 6, 2026
Apr 1, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.
1Alliedtelesis
8At Rg634a
At Rg634a FirmwareImg616lh+5 more
May 6, 2026
Mar 31, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary...Show more
The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to cli.html.Show less
1Fedoraproject
1389 Directory Server
May 6, 2026
Mar 18, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.
1Owncloud
2Owncloud
Owncloud Server
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.
2Puppet
Puppetlabs
2Puppet
Puppet Enterprise
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.
1Huawei
2E355
E355 Firmware
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remote attackers to change passwords and settings, or obtain sensitive information, via a direct request...Show more
The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remote attackers to change passwords and settings, or obtain sensitive information, via a direct request to (1) api/wlan/security-settings, (2) api/device/information, (3) api/wlan/basic-settings, (4) api/wlan/mac-filter, (5) api/monitoring/status, or (6) api/dhcp/settings.Show less