← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Taskdriver
1Taskdriver
Apr 23, 2026
Aug 10, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."
1Zope
1Zodb
Apr 23, 2026
Aug 7, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol.
2John Doe
Siemens
2Netport Software
Speedstream 5200
Apr 23, 2026
Aug 7, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a trailing dot in the hostname.
1Zeeways
1Shaadiclone
Apr 23, 2026
Aug 7, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php.
1Fedorahosted
1Sssd
Apr 23, 2026
Jul 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows context-dependent attackers to obtain ac...Show more
The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows context-dependent attackers to obtain access by sending the account's username, in conjunction with an arbitrary password, over an ssh connection.Show less
1Desiscripts
1Desi Short Url Script
Apr 23, 2026
Jul 28, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to 1 and the uid cookie to an integer value, as demonstrated by a value of 13.
2Six Apart
Sixapart
2Movable Type
Movable Type
Apr 23, 2026
Jul 16, 2009
N/A· v4
N/A· v3
5.8 MEDIUM· v2
mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive in...Show more
mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.Show less
1Xigla
1Absolute Live Support .net
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Xigla
1Absolute Form Processor.net
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Xigla
1Absolute Content Rotator
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Xigla
1Absolute Newsletter
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Xigla
1Absolute Poll Manager Xe
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Xigla
1Absolute Control Panel Xe
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Xigla
1Absolute Banner Manager.net
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Xigla
1Absolute Podcast.net
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Xigla
1Absolute News Manager.net
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Xigla
1Absolute News Feed
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.
1Xigla
1Absolute Faq Manager .net
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
1Wordpress
2Wordpress
Wordpress Mu
Apr 23, 2026
Jul 10, 2009
N/A· v4
N/A· v3
4.9 MEDIUM· v2
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the p...Show more
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.Show less
2Apple
Rubyonrails
3Mac Os X
Mac Os X ServerRuby On Rails
Apr 23, 2026
Jul 10, 2009
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the use...Show more
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.Show less