When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,371 vulnerabilities with CWE-287
CVE-2021-25490
MEDIUM
Keymaster <SMR Oct-2021 Release 1 - Privilege Escalation
CVSS 6.0
CVE-2021-25484
MEDIUM
InputManagerService <SMR Oct-2021 Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-0595
HIGH
Android 8.1-11 - Unauthenticated Work Profile Access via RootWindowContainer Lock Bypass
CVSS 7.8
CVE-2021-39226
CRITICAL
KEV
Grafana < 7.5.11 - Unauthenticated Snapshot Data Exposure and Deletion via Direct Path Access
CVSS 9.8
CVE-2021-41286
HIGH
Omikron MultiCash Desktop 4.00.008.SP5 - Code Injection
CVSS 7.8
CVE-2021-39872
MEDIUM
GitLab >=14.1.0 <14.1.7 - Improper Access Control via Expired Password Bypass
CVSS 6.5
CVE-2021-23857
CRITICAL
Bosch Rexroth IndraMotion MLC Firmware < 12 - Improper Authentication via Password Hash
CVSS 10.0
CVE-2021-35296
CRITICAL
PTCL HG150-Ub v3.0 - Authentication Bypass via Cookie and Response Path Manipulation
CVSS 9.8
CVE-2021-20578
CRITICAL
IBM Cloud Pak for Security - Privilege Escalation
CVSS 9.8
CVE-2021-24017
MEDIUM
FortiManager < 6.2.7 - Improper Authentication via Request Handler
CVSS 5.4
CVE-2021-41292
CRITICAL
ECOA BAS Controller - Unauthenticated Authentication Bypass via Cookie Poisoning
CVSS 9.8
CVE-2021-35943
CRITICAL
Couchbase Server <6.6.2 - Info Disclosure
CVSS 9.8
CVE-2021-38299
CRITICAL
webauthn_framwork 3.3.0-3.3.3 - Improper Authentication via User Presence Bypass
CVSS 9.8
CVE-2021-31606
HIGH
openvpn-monitor <= 1.1.3 - Authorization Bypass to Disconnect Clients
CVSS 7.5
CVE-2021-41503
HIGH
D-Link DCS-932L Firmware < 2.17 and DCS-5000L Firmware 1.05 - Improper Access Control via Basic Authentication
CVSS 8.0
CVE-2021-22869
CRITICAL
GitHub Enterprise Server - Privilege Escalation
CVSS 9.8
CVE-2021-31917
CRITICAL
Infinispan 10.0.0-12.0.0 & Red Hat DataGrid 8.0.0-8.1.1 - DIGEST Auth Bypass
CVSS 9.8
CVE-2021-38412
CRITICAL
Digi PortServer TS 16 Rack - Info Disclosure
CVSS 9.6
CVE-2021-41317
CRITICAL
xss_hunter_express < 2021-09-17 - Improper Authentication
CVSS 9.8
CVE-2021-41303
CRITICAL
Apache Shiro < 1.8.0 - Authentication Bypass via Spring Boot Integration
CVSS 9.8
CVE-2021-33045
CRITICAL
KEV
Dahua Multiple Devices Firmware - Authentication Bypass via Malicious Data Packet
CVSS 9.8
CVE-2021-33044
CRITICAL
KEV
Dahua IPC-HUM7XXX IPC-HX3XXX IPC-HX5XXX SD1A1 SD22 SD49 SD50 SD52C SD6AL TPC-BF1241 Firmware Authentication Bypass
CVSS 9.8
CVE-2021-33700
HIGH
SAP Business One <10.0 - Auth Bypass
CVSS 7.8
CVE-2021-39215
HIGH
Jitsi Meet < 2.0.5963 - Improper Authentication via Symmetrical JWT Validation
CVSS 7.5
CVE-2021-3145
MEDIUM
Ionic Identity Vault < 5.0 - Biometric Authentication Bypass
CVSS 6.7
Details
Vulnerabilities
4,371
Exploit Likelihood
High