When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,374 vulnerabilities with CWE-287
CVE-2014-0769
Festo CECX-X-C1/M1 CoDeSys/SoftMotion - Unauthenticated Config Mod & Log Deletion
CVE-2014-0760
Festo CECX-X-C1 and CECX-X-M1 Modular Controllers with CoDeSys - Improper Authentication via Undocumented FTP Access
CVE-2014-0188
Red Hat OpenShift Enterprise <2.0.5, 1.2.7 - Auth Bypass
CVE-2014-1295
Apple iOS < 7.1.1, OS X 10.8.x-10.9.2, and TVOS < 6.1.1 - Improper Authentication via Triple Handshake Attack
CVE-2014-2341
CubeCart < 5.2.9 - Session Fixation via PHPSESSID Parameter
CVE-2014-2665
MediaWiki <1.19.14, 1.20.x<1.21.8, 1.22.x<1.22.5 - Info Disclosure
CVE-2014-1517
Bugzilla 2.x-4.4.2 and 4.5.x < 4.5.3 - Authenticated Login CSRF
CVE-2014-1984
Cybozu Remote Service Manager <3.1.1 - Session Fixation
CVE-2014-2338
strongSwan 4.0.7-5.1.3 - Authentication Bypass via IKEv2 Rekeying
CVE-2014-2828
OpenStack Keystone - Denial of Service via Authentication Chaining
CVE-2014-0138
cURL/libcurl <7.36.0 - Open Redirect
CVE-2014-0357
Amtelco miSecureMessages - Info Disclosure
CVE-2014-0353
ZyXEL Wireless N300 NetUSB NBG-419N <1.00(BFQ.6)C0 - Auth Bypass
CVE-2014-0348
Artiva Workstation <1.3.9 - Auth Bypass
CVE-2014-2128
Cisco ASA 8.2-9.1 Authentication Bypass via Crafted Cookie/URL
CVE-2014-0166
WordPress <3.7.2, <3.8.2 - Info Disclosure
CVE-2014-0635
EMC VPLEX GeoSynchrony 4.x-5.x - Session Fixation
CVE-2014-1982
Allied Telesis AT-RG634A, iMG624A, iMG616LH, iMG646BD - Unauthenticated Remote Code Execution via CLI Interface
CVE-2014-0132
389 Directory Server <1.2.11.26 - Privilege Escalation
CVE-2014-2047
owncloud < 6.0.2 - Session Fixation via GET Request
CVE-2014-1911
Foscam FI8910W <11.37.2.55 - Info Disclosure
CVE-2014-2075
TIBCO Enterprise Administrator <1.0.0 - Command Injection
CVE-2014-0743
Cisco Unified Communications Manager < 10.0(1) - Unauthenticated Authentication Bypass in CAPF
CVE-2014-0739
Cisco Adaptive Security Appliance Software 9.1(.3) - Unauthenticated Authentication Bypass via Phone Proxy TFTP Request
CVE-2014-0738
Cisco Adaptive Security Appliance Software 9.1(.3) - Authentication Bypass via CTL File Injection
Details
Vulnerabilities
4,374
Exploit Likelihood
High