← Back
CWE-287

4,777 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,777)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bug Software
1Bughotel Reservation System
Apr 23, 2026
Nov 16, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this...Show more
Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Testlink
1Testlink
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to "handling of keyboar...Show more
The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to "handling of keyboard focus between secure text fields."Show less
1Apple
1Mac Os X
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack.
1Bti Tracker
1Bti Tracker
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.
1Bti Tracker
1Bti Tracker
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrar...Show more
details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.Show less
1Apple
1Safari
Apr 23, 2026
Nov 15, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing att...Show more
The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.Show less
1Ruby Lang
1Ruby
Apr 23, 2026
Nov 14, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a re...Show more
The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the commonName (CN) field in a server certificate matches the domain name in a request sent over SSL, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site, different components than CVE-2007-5162.Show less
1Jean Charles
1Jbc Explorer
Apr 23, 2026
Nov 10, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with...Show more
dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password parameters.Show less
1Apache
1Geronimo
Apr 23, 2026
Nov 3, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the...Show more
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.Show less
1Vonage
1Motorola Phone Adapter Vt2142 Vd
Apr 23, 2026
Nov 1, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows remote attackers to send spoofed INVITE messages, as demonstrated by a flo...Show more
The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows remote attackers to send spoofed INVITE messages, as demonstrated by a flood of messages triggering a denial of service, and by phone calls with malicious content.Show less
1Agtc Websolutions
1Php Agtc Membership System
Apr 23, 2026
Oct 31, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel...Show more
adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges.Show less
1Gentoo
1Mldonkey Ebuild
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.
1Secureideas
1Basic Analysis And Security Engine
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication via (1) base_main.php, (2) base_qry_alert.php, and poss...Show more
Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication via (1) base_main.php, (2) base_qry_alert.php, and possibly other vectors.Show less
1Hp
1Select Identity
Apr 23, 2026
Oct 12, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in HP Select Identity 4.01 through 4.01.010 and 4.10 through 4.13.001 allows remote attackers to obtain unspecified access via unknown vectors.
2Alcatel
Bt
2Home Hub
Speedtouch 7g Router
Apr 23, 2026
Oct 12, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash...Show more
The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the end of the PATH_INFO to cgi/b, aka "double-slash auth bypass." NOTE: remote attackers outside the intranet can exploit this by leveraging a separate CSRF vulnerability. NOTE: SpeedTouch 780 might also be affected by some of these issues.Show less
1Lightblog
1Lightblog
Apr 23, 2026
Oct 11, 2007
N/A· v4
N/A· v3
6.5 MEDIUM· v2
cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.
2Broadcom
Ca
3Brightstor Arcserve Backup Laptops Desktops
Desktop Management SuiteProtection Suites
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete user...Show more
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer is authenticated, which allows remote attackers to add and delete users, and start client restores.Show less
1Ruby Lang
1Ruby
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS r...Show more
The connect method in lib/net/http.rb in the (1) Net::HTTP and (2) Net::HTTPS libraries in Ruby 1.8.5 and 1.8.6 does not verify that the commonName (CN) field in a server certificate matches the domain name in an HTTPS request, which makes it easier for remote attackers to intercept SSL transmissions via a man-in-the-middle attack or spoofed web site.Show less
1Sun
2Java System Access Manager
Java System Application Server
Apr 23, 2026
Oct 1, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative...Show more
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.Show less