← Back
CWE-287

4,777 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,777)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Belkin
1F5d9230 4
Apr 23, 2026
Jan 23, 2008
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to read and modify configuration via a direct request to SaveCfgFile.cgi.
1Alilg
1Alitalk
Apr 23, 2026
Jan 23, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.
1News
1Micronews
Apr 23, 2026
Jan 22, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
MicroNews allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin.php.
1Evilsentinel
1Evilsentinel
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.
1Radiator
1Radius Server
Apr 23, 2026
Jan 17, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, as demonstrated by packets sent by nmap.
1Level One
1Wbr 3460a
Apr 23, 2026
Jan 10, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The telnet service in LevelOne WBR-3460 4-Port ADSL 2/2+ Wireless Modem Router with firmware 1.00.11 and 1.00.12 does not require authentication, which allows remote attackers on the local or wireless network to obtain a...Show more
The telnet service in LevelOne WBR-3460 4-Port ADSL 2/2+ Wireless Modem Router with firmware 1.00.11 and 1.00.12 does not require authentication, which allows remote attackers on the local or wireless network to obtain administrative access.Show less
1Uebimiau
1Webmail
Apr 23, 2026
Jan 10, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE:...Show more
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.Show less
3Debian
FedoraprojectPostgresql
3Debian Linux
FedoraPostgresql
Apr 23, 2026
Jan 9, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileg...Show more
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.Show less
1Aruba Networks
1Aruba Mobility Controllers
Apr 23, 2026
Jan 9, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.11-FIPS or earlier allows remote attackers to bypass authentication mech...Show more
Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.11-FIPS or earlier allows remote attackers to bypass authentication mechanisms and obtain management or VPN interface access.Show less
1Asterisk
2Asterisk Business Edition
Open Source
Apr 23, 2026
Dec 20, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication...Show more
Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is correct and there is no password, which allows remote attackers to bypass authentication using a valid username.Show less
1Apple
1Mac Os X
Apr 23, 2026
Dec 19, 2007
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Mail in Apple Mac OS X 10.4.11 and 10.5.1, when an SMTP account has been set up using Account Assistant, can use plaintext authentication even when MD5 Challenge-Response authentication is available, which makes it easie...Show more
Mail in Apple Mac OS X 10.4.11 and 10.5.1, when an SMTP account has been set up using Account Assistant, can use plaintext authentication even when MD5 Challenge-Response authentication is available, which makes it easier for remote attackers to sniff account activity.Show less
1Apple
1Mac Os X
Apr 23, 2026
Dec 18, 2007
N/A· v4
N/A· v3
9.4 HIGH· v2
Java in Mac OS X 10.4 through 10.4.11 allows remote attackers to bypass Keychain access controls and add or delete arbitrary Keychain items via a crafted Java applet.
1Flat Php
1Board
Apr 23, 2026
Dec 17, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrary user account via the fpb_username cookie.
1Kerio
1Winroute Firewall
Apr 23, 2026
Dec 15, 2007
N/A· v4
N/A· v3
2.1 LOW· v2
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege...Show more
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.Show less
1Bea
1Weblogic Mobility Server
Apr 23, 2026
Dec 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in the Image Converter functionality in BEA WebLogic Mobility Server 3.3, 3.5, and 3.6 through 3.6 SP1 allows remote attackers to obtain application file and resource access via unspecified vect...Show more
Unspecified vulnerability in the Image Converter functionality in BEA WebLogic Mobility Server 3.3, 3.5, and 3.6 through 3.6 SP1 allows remote attackers to obtain application file and resource access via unspecified vectors.Show less
1Deluxebb
1Deluxebb
Apr 23, 2026
Dec 4, 2007
N/A· v4
N/A· v3
9.0 HIGH· v2
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary...Show more
cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php.Show less
1Ftp Admin
1Ftp Admin
Apr 23, 2026
Dec 4, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.
1Apc
2Oas
Switched Rack Pdu Firmware
Apr 23, 2026
Dec 4, 2007
N/A· v4
N/A· v3
7.1 HIGH· v2
The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remote attackers to bypass authentication and obtain login access by making a login a...Show more
The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remote attackers to bypass authentication and obtain login access by making a login attempt while a different client is logged in, and then resubmitting the login attempt once the other client exits.Show less
1Hitachi
1Jp1 File Transmission Server
Apr 23, 2026
Nov 27, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-01 allows remote attackers to bypass authentication and "view files" via unspecified vectors.
1Gnu
1Gnump3d
Apr 23, 2026
Nov 26, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
gnump3d 2.9final does not apply password protection to its plugins, which might allow remote attackers to bypass intended access restrictions.