← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Everfocus
1Edr1600
Apr 23, 2026
Oct 30, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors.
1Tim Nelson
1Shared Sign On
Apr 23, 2026
Oct 9, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vectors.
1Isygen
1Com Icrmbasic
Apr 23, 2026
Sep 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this i...Show more
A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspecified impact and remote attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Alienvault
1Ossim
Apr 23, 2026
Sep 28, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to bypass authentication, and read graphs or infrastructure information, via a direct request to (1) graphs/alarms_events.php or (2...Show more
Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to bypass authentication, and read graphs or infrastructure information, via a direct request to (1) graphs/alarms_events.php or (2) host/draw_tree.php.Show less
1Cisco
1Ios
Apr 23, 2026
Sep 28, 2009
N/A· v4
N/A· v3
7.1 HIGH· v2
Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.
1Zenas
1Paolink
Apr 23, 2026
Sep 25, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
1Zenas
1Paoliber
Apr 23, 2026
Sep 25, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
1Zenas
1Pao Bacheca Guestbook
Apr 23, 2026
Sep 25, 2009
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
1Livestreet
1Livestreet
Apr 23, 2026
Sep 18, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE operations via unspecified vectors.
1Canonical
1Ubuntu Linux
Apr 23, 2026
Sep 17, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to b...Show more
pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.Show less
5Canonical
FedoraprojectOpensuse+2 more
6Fedora
Linux EnterpriseLinux Enterprise Server+3 more
Apr 23, 2026
Sep 17, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
1Carsten Wulff
1Simplephpweb
Apr 23, 2026
Sep 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third p...Show more
admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third party information.Show less
1Symantec
1Altiris Deployment Solution
Apr 23, 2026
Sep 8, 2009
N/A· v4
N/A· v3
4.8 MEDIUM· v2
Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tas...Show more
Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.Show less
1Otmanager
1Otmanager Cms
Apr 23, 2026
Sep 8, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADMIN_Nome cookies to certain values, as reachable in Admin/index.php.
1Gnome
1Gdm
Apr 23, 2026
Sep 4, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via...Show more
The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079.Show less
1Ekinboard
1Ekinboard
Apr 23, 2026
Sep 2, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by setting the _groups[] parameter to 2, as demonstrated via backup.php.
1Zkup
1Zkup
Apr 23, 2026
Aug 31, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding...Show more
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator.Show less
1Maianscriptworld
1Maian Greetings
Apr 23, 2026
Aug 26, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin.
1Raidsonic
1Icy Box Nas
Apr 23, 2026
Aug 25, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this i...Show more
userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Ajsquare
1Aj Article
Apr 23, 2026
Aug 24, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.ph...Show more
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php, and (11) logo.php in admin/.Show less