← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Manageengine
1Servicedesk Plus
Apr 29, 2026
Jul 17, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.
1Ulli Horlacher
1Fex
Apr 29, 2026
Jun 24, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication and upload arbitrary files via a request that lacks an authentication ID.
1Creloaded
1Cre Loaded
Apr 29, 2026
Jun 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_t...Show more
CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.Show less
1Creloaded
1Cre Loaded
Apr 29, 2026
Jun 8, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password_forgotten.php append...Show more
CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password_forgotten.php appended as the PATH_INFO, which bypasses a check that uses PHP_SELF, which is not properly handled by (a) includes/application_top.php and (b) admin/includes/application_top.php, as exploited in the wild in 2009.Show less
1Fedoraproject
1Sssd
Apr 29, 2026
May 26, 2011
N/A· v4
N/A· v3
3.7 LOW· v2
The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname stri...Show more
The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.Show less
1Mediawiki
1Mediawiki
Apr 29, 2026
May 23, 2011
N/A· v4
N/A· v3
5.8 MEDIUM· v2
includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by...Show more
includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth token fails, which allows remote attackers to bypass authentication by creating crafted wikiUserID and wikiUserName cookies, or by leveraging an unattended workstation.Show less
1Smartertools
1Smarterstats
Apr 29, 2026
May 20, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentica...Show more
Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation.Show less
1Proofpoint
2Messaging Security Gateway
Protection Server
Apr 29, 2026
May 5, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
The mail-filter web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to bypass authen...Show more
The mail-filter web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to bypass authentication via unspecified vectors.Show less
1Netgear
2Prosafe Wnap210
Prosafe Wnap210 Firmware
Apr 29, 2026
Apr 10, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The NetGear ProSafe WNAP210 with firmware 2.0.12 allows remote attackers to bypass authentication and obtain access to the configuration page by visiting recreate.php and then visiting index.php.
1Ibm
1Aix
Apr 29, 2026
Apr 5, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentication via a login attempt with an arbitrary password.
1Nokia
2E75
E75 Firmware
Apr 29, 2026
Mar 29, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.
1Ibm
1Lotus Domino
Apr 29, 2026
Mar 25, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physically proximate attackers to perform administrative changes or obtain sensi...Show more
The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physically proximate attackers to perform administrative changes or obtain sensitive information via a (1) Load, (2) Tell, or (3) Set Configuration command.Show less
1Ibm
1Lotus Domino
Apr 29, 2026
Mar 25, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authenticat...Show more
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.Show less
1Openldap
1Openldap
Apr 29, 2026
Mar 20, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attackers to bypass intended access restrictions via an arbitrary password.
1Arthurdejong
1Nss Pam Ldapd
Apr 29, 2026
Mar 15, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass authentication.
1Gplhost
1Domain Technologie Control
Apr 29, 2026
Mar 7, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth infor...Show more
Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which allows remote attackers to obtain potentially sensitive bandwidth information via a direct request.Show less
1Hp
1Multifunction Peripheral Digital Sending Software
Apr 29, 2026
Mar 7, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via...Show more
HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to require authentication.Show less
1Redhat
1Network Satellite Server
Apr 29, 2026
Feb 25, 2011
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks.
1Cisco
2Telepresence Recording Server
Telepresence Recording Server Software
Apr 29, 2026
Feb 25, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug...Show more
Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug ID CSCtg35833.Show less
1Cisco
2Telepresence Multipoint Switch
Telepresence Multipoint Switch Software
Apr 29, 2026
Feb 25, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote a...Show more
The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug ID CSCtf01253.Show less