When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,320 vulnerabilities with CWE-287
CVE-2025-55340
HIGH
Windows Remote Desktop - Privilege Escalation
CVSS 7.0
CVE-2025-53845
MEDIUM
Fortinet FortiAnalyzer <7.6.3 - Info Disclosure
CVSS 6.5
CVE-2025-9064
CRITICAL
FactoryTalk View Machine Edition - Path Traversal
CVSS 9.1
CVE-2025-9063
CRITICAL
FactoryTalk View Machine Edition - Auth Bypass
CVSS 9.8
CVE-2025-9265
CRITICAL
Kiloview NDI N30 < 2.02.246 - Unauthenticated Broken Authorization
CVE-2025-11661
HIGH
oranbyte School Management System - Improper Authentication
CVSS 7.3
CVE-2025-11633
LOW
Furbo 360 Dog Camera <036 & Furbo Mini <074 - Improper Certificate Validation
CVSS 3.7
CVE-2025-61884
HIGH
KEV
Oracle Configurator 12.2.3-12.2.14 - Unauthenticated CRLF Injection via Runtime UI
CVSS 7.5
CVE-2025-60306
CRITICAL
code-projects Simple Car Rental System 1.0 - Auth Bypass
CVSS 9.9
CVE-2025-11529
HIGH
ChurchCRM < 5.19.0 - Authentication Bypass in AuthMiddleware
CVSS 7.3
CVE-2025-11192
HIGH
Extreme Networks Fabric Engine <9.3 - Privilege Escalation
CVSS 8.6
CVE-2025-11287
HIGH
samanhappy MCPHub <0.9.10 - Auth Bypass
CVSS 7.3
CVE-2025-61882
CRITICAL
KEV
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
CVSS 9.8
CVE-2025-61679
HIGH
anyquery < 0.4.4 - Unauthenticated Exposure of Sensitive Integration Data via HTTP Server
CVSS 7.7
CVE-2025-54154
MEDIUM
QNAP Authenticator 1.3.0-1.3.1.1226 - Improper Authentication
CVSS 6.8
CVE-2025-61665
HIGH
WeGIA < 3.5.0 - Unauthenticated Sensitive Information Exposure via get_relatorios_socios.php Endpoint
CVSS 7.5
CVE-2025-41064
CRITICAL
GTT OpenSIAC - Improper Authentication via Cl@ve Impersonation
CVE-2025-11130
HIGH
iHongRen pptp-vpn 1.0/1.0.1 - Missing Authentication
CVSS 8.4
CVE-2025-59934
CRITICAL
formbricks < 4.0.1 - Unauthenticated Authentication Bypass via JWT Signature Verification Missing
CVSS 9.4
CVE-2025-20160
HIGH
Cisco IOS Software - Info Disclosure
CVSS 8.1
CVE-2025-10906
HIGH
Magnetism Studios Endurance <3.3.0 - Use After Free
CVSS 8.4
CVE-2025-0672
LOW
WSO2 Identity Server - Authentication Bypass via FIDO Registration Data
CVSS 3.3
CVE-2025-0663
MEDIUM
WSO2 Identity Server - Cross-Tenant Authentication Bypass via Adaptive Authentication Cookie Forgery
CVSS 6.8
CVE-2025-9965
CRITICAL
Novakon P series < P-2.0.05 - Unauthenticated Arbitrary Application Upload/Download
CVE-2025-57434
HIGH
Creacast Creabox Manager - Improper Authentication via Password Prefix Bypass
CVSS 8.8
Details
Vulnerabilities
4,320
Exploit Likelihood
High