← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dlink
1Dir 615
Apr 29, 2026
Apr 27, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the secur...Show more
The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for the Wi-Fi network via unspecified vectors, or (3) modify DNS settings via unspecified vectors.Show less
1Graugon
1Php Article Publisher
Apr 29, 2026
Apr 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1.
1Digitalinterchange
1Digital Interchange Document Library
Apr 29, 2026
Apr 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors....Show more
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. NOTE: some of these details are obtained from third party information.Show less
1Will Kraft
1Ez Blog
Apr 29, 2026
Apr 23, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.
1Alvaro
1Alvaros Messenger
Apr 29, 2026
Apr 20, 2010
N/A· v4
N/A· v3
5.8 MEDIUM· v2
aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509...Show more
aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary certificate.Show less
1Ca
3Xosoft Content Distribution
Xosoft High AvailabilityXosoft Replication
Apr 29, 2026
Apr 7, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP request.
1Ca
3Xosoft Content Distribution
Xosoft High AvailabilityXosoft Replication
Apr 29, 2026
Apr 7, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.
1Varnish.projects.linpro
1Varnish
Apr 29, 2026
Apr 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port,...Show more
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim's location on a trusted network and improper input validation of directives. NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless.Show less
1Sahanafoundation
1Sahana
Apr 29, 2026
Mar 31, 2010
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl...Show more
Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl_enable_acl action to the admin module.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 30, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspec...Show more
Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to obtain potentially sensitive information from Open Directory via unspecified LDAP requests.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 29, 2026
Mar 30, 2010
N/A· v4
N/A· v3
7.2 HIGH· v2
Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.
1Dedecms
1Dedecms
Apr 29, 2026
Mar 24, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] paramet...Show more
include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain administrative access via a value of 1 for the _SESSION[dede_admin_id] parameter, as demonstrated by a request to uploads/include/dialog/select_soft_post.php.Show less
1Tejimaya
1Openpne
Apr 29, 2026
Mar 23, 2010
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login"...Show more
The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login" functionality via unknown vectors related to spoofing.Show less
1Marcus Krause
1T3sec Saltedpw
Apr 29, 2026
Mar 19, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.
1Hp
1Openview Performance Insight
Apr 29, 2026
Mar 10, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via ve...Show more
The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.Show less
1Mole Group
1Gastro Portal (restaurant Directory) Script
Apr 29, 2026
Mar 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows remote attackers to change the admin password via an unspecified form...Show more
admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows remote attackers to change the admin password via an unspecified form submission.Show less
1Beaussier
1Roomphplanning
Apr 29, 2026
Mar 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cookie to a value associated with the admin account.
1Beaussier
1Roomphplanning
Apr 29, 2026
Mar 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary rooms via the room parameter.
1Omidrouhani
1Xerver
Apr 29, 2026
Mar 3, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action...Show more
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.Show less
1Wikyblog
1Wikyblog
Apr 29, 2026
Feb 27, 2010
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.ph...Show more
Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.php/Edit/Main.Show less