When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,374 vulnerabilities with CWE-287
CVE-2013-2944
strongSwan 4.3.5-5.0.3 - Improper Authentication via Invalid ECDSA Signature
CVE-2013-1186
Cisco UCS <1.4(4)-2.0(2m - Auth Bypass
CVE-2013-3268
Novell iManager <2.7 - Info Disclosure
CVE-2013-0540
IBM WAS Liberty Profile <8.5.0.2 - Auth Bypass
CVE-2013-3060
Apache ActiveMQ <5.8.0 - Info Disclosure/DoS
CVE-2013-0314
JBoss Enterprise Portal Platform 5.2.2 - Improper Authentication in GateIn Portal Export/Import Gadget
CVE-2013-0282
OpenStack Keystone < 2012.1.3, 2012.1.x-2012.2.x, < 2013.1 - Improper Authentication via EC2-Style Authentication
CVE-2013-1155
Cisco FWSM <3.2(20.1)/4.0(15.2)/4.1(5.1) DoS via Auth-Proxy URL
CVE-2013-1150
Cisco ASA Software DoS via Crafted URL
CVE-2013-2743
BackupBuddy 1.3.4, 2.1.4, 2.2.25, 2.2.28, 2.2.4 - Unauthenticated Authentication Bypass via Step Parameter
CVE-2013-2741
BackupBuddy <2.2.28 - Info Disclosure
CVE-2013-1080
Novell ZENworks Configuration Management < 11.2.4 - Directory Traversal & Arbitrary File Upload
CVE-2013-0935
EMC Smarts Network Configuration Manager < 9.1 - Unauthenticated Remote Code Execution via Java RMI
CVE-2013-0258
Google Authenticator Login Module for Drupal 7.x - Unauthenticated Authentication Bypass
CVE-2013-0487
IBM Domino 8.5.x - Privilege Escalation
CVE-2013-1865
OpenStack Keystone Folsom 2012.2 - Improper Authentication via Revoked PKI Token Bypass
CVE-2013-0239
Apache CXF < 2.5.9, 2.6.x < 2.6.6, 2.7.x < 2.7.3 - Unauthenticated Authentication Bypass via Missing Password Element
CVE-2013-0910
Google Chrome <25.0.1364.152 - Auth Bypass
CVE-2013-1134
Cisco Unified Communications Manager <9.1(1) - DoS
CVE-2013-1405
VMware vCenter Server 4.0-4.1 and VirtualCenter 2.5 - Improper Authentication
CVE-2013-0209
Movable Type 4.2x, 4.3x Web Upgrade Remote Code Execution
CVE-2013-0759
Mozilla Firefox < 18.0 - Address Bar Spoofing via URL Userinfo Field
CVE-2013-0625
CRITICAL
KEV
Adobe ColdFusion <9.0.2 - Auth Bypass
CVSS 9.8
CVE-2012-10001
CRITICAL
WordPress Limit Login Attempts <1.7.1 - Info Disclosure
CVSS 9.8
CVE-2012-6340
MEDIUM
NETGEAR WGR614 v7 and v9 - Improper Authentication via Hardcoded Serial Credential
CVSS 4.6
Details
Vulnerabilities
4,374
Exploit Likelihood
High