VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

462 CVEsRSS

CVE-2025-66039Critical· 9.8PoC
9mo ago

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an…

▾ Abyssalsangoma · freepbxEPSS 3.3%via NVD
CVE-2025-64055Critical· 9.8
9mo ago

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.

▾ Midnightfanvil · x210_firmwareEPSS 0.52%via NVD
CVE-2025-59704Medium· 4.6
9mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password.

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow an attacker to gain access the the BIOS menu because is has no password.

▾ Sunlitentrust · nshield_5c_firmwareEPSS 0.26%via NVD
CVE-2025-64432Medium· 4.7PoC
10mo ago

KubeVirt is a virtual machine management add-on for Kubernetes

KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. I…

▾ Twilightkubevirt · kubevirtEPSS 0.14%via NVD
CVE-2025-56447Critical· 9.8
11mo ago

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

▾ MidnightEPSS 0.29%via NVD
CVE-2025-61884High· 7.5CISA KEVPoC
11mo ago

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI)

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network …

▾ Abyssaloracle · configuratorEPSS 96%via NVD
CVE-2025-61882Critical· 9.8CISA KEV0dayPoC
11mo ago

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration)

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated…

▾ Hadaloracle · concurrent_processingEPSS 100%via NVD
CVE-2025-10906High· 8.4
1y ago

A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS

A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper …

▾ TwilightEPSS 0.22%via NVD
CVE-2025-20160High· 8.1
1y ago

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists …

▾ Twilightcisco · iosEPSS 0.43%via NVD
CVE-2025-9994Critical· 9.8
1y ago

The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access.

The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access.

▾ MidnightEPSS 0.53%via NVD
CVE-2025-9815High· 7.8
1y ago

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing aut…

▾ Twilightalaneuler · batterykidEPSS 0.27%via NVD
CVE-2025-52054Medium· 5.3
1y ago

An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05

An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device.…

▾ Sunlittenda · ac8_firmwareEPSS 0.32%via NVD
CVE-2025-49706Medium· 6.5CISA KEVPoC
1y ago

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ Midnightmicrosoft · sharepoint_enterprise_serverEPSS 99%via NVD
CVE-2025-3910Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

▾ Sunlitredhat · build_of_keycloakEPSS 0.44%via NVD
CVE-2025-0604Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are ex…

▾ SunlitRed Hat · keycloak-ldap-federationEPSS 0.59%via NVD
CVE-2024-53704Critical· 9.8CISA KEVPoC
1y ago

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

▾ Hadalsonicwall · sonicosEPSS 95%via NVD
CVE-2024-49039High· 8.8CISA KEV0dayPoC
1y ago

Windows Task Scheduler Elevation of Privilege Vulnerability

Windows Task Scheduler Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 14%via NVD
CVE-2024-10963High· 7.4
1y ago

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized acces…

▾ TwilightEPSS 0.78%via NVD
CVE-2024-35248High· 7.3
2y ago

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · dynamics_365_business_centralEPSS 0.95%via NVD
CVE-2023-46805High· 8.2CISA KEV0dayPoC
2y ago

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

▾ Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2023-49105Critical· 9.8CISA KEVPoC
2y ago

An issue was discovered in ownCloud owncloud/core before 10.13.1

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs b…

▾ Hadalowncloud · owncloud_serverEPSS 43%via NVD
CVE-2023-4501Critical· 9.8
3y ago

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), vers…

User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), vers…

▾ Midnightmicrofocus · cobol_serverEPSS 0.75%via NVD
CVE-2023-35078Critical· 9.8CISA KEV0dayPoC
3y ago

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

▾ Hadalivanti · endpoint_manager_mobileEPSS 100%via NVD
CVE-2023-28461Critical· 9.8CISA KEV
3y ago

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could…

▾ Hadalarraynetworks · arrayos_agEPSS 68%via NVD
CVE-2022-40684Critical· 9.8CISA KEV0dayPoC
3y ago

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 …

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 …

▾ Hadalfortinet · fortiproxyEPSS 100%via NVD
CVE-2022-35203High· 7.2
4y ago

An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.

An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.

▾ Twilighttrendnet · tv-ip572pi_firmwareEPSS 1.2%via NVD
CVE-2022-36524High· 7.5
4y ago

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.

▾ Twilightdlink · go-rt-ac750_firmwareEPSS 0.86%via NVD
CVE-2022-30034High· 8.6
4y ago

Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass

Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to discover and invoke arbitrary Celery RPC calls or deny s…

▾ Twilightflower_project · flowerEPSS 1.1%via NVD
CVE-2021-36460High· 7.8PoC
4y ago

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords

VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allow…

▾ Midnightveryfitpro_project · veryfitproEPSS 0.36%via NVD
CVE-2022-29534High· 7.5
4y ago

An issue was discovered in MISP before 2.4.158

An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

▾ Twilightmisp-project · mispEPSS 1.6%via NVD
CWE-287 vulnerabilities (CVEs) — page 15 · VulnSea