CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,371 vulnerabilities with CWE-287
CVE-2021-25490 MEDIUM
Keymaster <SMR Oct-2021 Release 1 - Privilege Escalation
CVSS 6.0
CVE-2021-25484 MEDIUM
InputManagerService <SMR Oct-2021 Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-0595 HIGH
Android 8.1-11 - Unauthenticated Work Profile Access via RootWindowContainer Lock Bypass
CVSS 7.8
CVE-2021-39226 CRITICAL KEV
Grafana < 7.5.11 - Unauthenticated Snapshot Data Exposure and Deletion via Direct Path Access
CVSS 9.8
CVE-2021-41286 HIGH
Omikron MultiCash Desktop 4.00.008.SP5 - Code Injection
CVSS 7.8
CVE-2021-39872 MEDIUM
GitLab >=14.1.0 <14.1.7 - Improper Access Control via Expired Password Bypass
CVSS 6.5
CVE-2021-23857 CRITICAL
Bosch Rexroth IndraMotion MLC Firmware < 12 - Improper Authentication via Password Hash
CVSS 10.0
CVE-2021-35296 CRITICAL
PTCL HG150-Ub v3.0 - Authentication Bypass via Cookie and Response Path Manipulation
CVSS 9.8
CVE-2021-20578 CRITICAL
IBM Cloud Pak for Security - Privilege Escalation
CVSS 9.8
CVE-2021-24017 MEDIUM
FortiManager < 6.2.7 - Improper Authentication via Request Handler
CVSS 5.4
CVE-2021-41292 CRITICAL
ECOA BAS Controller - Unauthenticated Authentication Bypass via Cookie Poisoning
CVSS 9.8
CVE-2021-35943 CRITICAL
Couchbase Server <6.6.2 - Info Disclosure
CVSS 9.8
CVE-2021-38299 CRITICAL
webauthn_framwork 3.3.0-3.3.3 - Improper Authentication via User Presence Bypass
CVSS 9.8
CVE-2021-31606 HIGH
openvpn-monitor <= 1.1.3 - Authorization Bypass to Disconnect Clients
CVSS 7.5
CVE-2021-41503 HIGH
D-Link DCS-932L Firmware < 2.17 and DCS-5000L Firmware 1.05 - Improper Access Control via Basic Authentication
CVSS 8.0
CVE-2021-22869 CRITICAL
GitHub Enterprise Server - Privilege Escalation
CVSS 9.8
CVE-2021-31917 CRITICAL
Infinispan 10.0.0-12.0.0 & Red Hat DataGrid 8.0.0-8.1.1 - DIGEST Auth Bypass
CVSS 9.8
CVE-2021-38412 CRITICAL
Digi PortServer TS 16 Rack - Info Disclosure
CVSS 9.6
CVE-2021-41317 CRITICAL
xss_hunter_express < 2021-09-17 - Improper Authentication
CVSS 9.8
CVE-2021-41303 CRITICAL
Apache Shiro < 1.8.0 - Authentication Bypass via Spring Boot Integration
CVSS 9.8
CVE-2021-33045 CRITICAL KEV
Dahua Multiple Devices Firmware - Authentication Bypass via Malicious Data Packet
CVSS 9.8
CVE-2021-33044 CRITICAL KEV
Dahua IPC-HUM7XXX IPC-HX3XXX IPC-HX5XXX SD1A1 SD22 SD49 SD50 SD52C SD6AL TPC-BF1241 Firmware Authentication Bypass
CVSS 9.8
CVE-2021-33700 HIGH
SAP Business One <10.0 - Auth Bypass
CVSS 7.8
CVE-2021-39215 HIGH
Jitsi Meet < 2.0.5963 - Improper Authentication via Symmetrical JWT Validation
CVSS 7.5
CVE-2021-3145 MEDIUM
Ionic Identity Vault < 5.0 - Biometric Authentication Bypass
CVSS 6.7
Details
Vulnerabilities 4,371
Exploit Likelihood High