CWE-287
4,475 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CVEs (4,475)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ptzoptics 2Pt30x Ndi Xx G2 Firmware Pt30x Sdi FirmwareJun 17, 2026 Sep 17, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Au...Show more |
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication. |
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication. |
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access...Show more |
1Rockwellautomation 1Factorytalk Batch View Jun 17, 2026 Sep 12, 2024 9.2 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the t...Show more |
1Eclipse 1Eclipse Dataspace Components Jun 17, 2026 Sep 11, 2024 5.1 MEDIUM· v4 8.1 HIGH· v3 N/A· v2 In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an...Show more |
1Microsoft 1Dynamics 365 Business Central Jun 17, 2026 Sep 10, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability |
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function. |
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA. |
An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vul...Show more |
1Trellix 1Intrusion Prevention System Manager Jun 17, 2026 Sep 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager. |
1Trellix 1Intrusion Prevention System Manager Jun 17, 2026 Sep 5, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly |
ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a result, an attacker c...Show more |
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly...Show more |
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting...Show more |
The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 and 10.4.2, respective...Show more |
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. This has been corrected so that default certificat...Show more |
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and passwo...Show more |
The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional securi...Show more |
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality. |