CWE-287
4,464 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,464)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The goTenna Pro App does not authenticate public keys which allows an
unauthenticated attacker to manipulate messages. It is advised to update
your app to the current release for enhanced encryption protocols. |
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a number of preconditions, the `highest_available` setting will incorrectly assume that the identity’...Show more |
An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Cl...Show more |
Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. Nodes can communicate directly via an internet conn...Show more |
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array. |
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication. |
The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. Prior to this patch being applied it might be possible for an attacker...Show more |
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects...Show more |
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the de...Show more |
1Ptzoptics 2Pt30x Ndi Xx G2 Firmware Pt30x Sdi FirmwareJun 17, 2026 Sep 17, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Au...Show more |
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication. |
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication. |
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access...Show more |
1Rockwellautomation 1Factorytalk Batch View Jun 17, 2026 Sep 12, 2024 9.2 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the t...Show more |
1Eclipse 1Eclipse Dataspace Components Jun 17, 2026 Sep 11, 2024 5.1 MEDIUM· v4 8.1 HIGH· v3 N/A· v2 In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an...Show more |
1Microsoft 1Dynamics 365 Business Central Jun 17, 2026 Sep 10, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability |
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function. |
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA. |
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vul...Show more |
1Trellix 1Intrusion Prevention System Manager Jun 17, 2026 Sep 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager. |