Vulnerabilities (CVE)

Filtered by CWE-287
Total 4916 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-60890 1 Oracle 1 Payroll 2026-08-12 N/A 8.8 HIGH
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2026-62827 1 Microsoft 1 Sharepoint Server 2026-08-12 N/A 8.8 HIGH
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2021-22893 1 Ivanti 1 Connect Secure 2026-08-12 7.5 HIGH 10.0 CRITICAL
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.
CVE-2020-12812 1 Fortinet 1 Fortios 2026-08-12 7.5 HIGH 9.8 CRITICAL
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.
CVE-2026-54635 2026-08-11 N/A 7.5 HIGH
pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization header when a webhook handler is registered with the documented path argument, because setup() stores bearer tokens only under the default suffix paths and never adds the custom path to the token map, so self._tokens.get(path) returns None and the authentication guard is skipped. An unauthenticated remote attacker can POST forged payloads to the custom webhook endpoint and trigger victim-defined handlers. This issue is fixed in version 2.2.1.
CVE-2020-3565 1 Cisco 1 Secure Firewall Threat Defense 2026-08-11 4.3 MEDIUM 5.8 MEDIUM
A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices on an affected system. The vulnerability exists because TCP Intercept is invoked when the embryonic connection limit is reached, which can cause the underlying detection engine to process the packet incorrectly. An attacker could exploit this vulnerability by sending a crafted stream of traffic that matches a policy on which TCP Intercept is configured. A successful exploit could allow the attacker to match on an incorrect policy, which could allow the traffic to be forwarded when it should be dropped. In addition, the traffic could incorrectly be dropped.
CVE-2019-1980 1 Cisco 3 Firepower Services Software For Asa, Secure Firewall Management Center, Secure Firewall Threat Defense 2026-08-11 5.0 MEDIUM 5.3 MEDIUM
A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper detection of the initial use of a protocol on a nonstandard port. An attacker could exploit this vulnerability by sending traffic on a nonstandard port for the protocol in use through an affected device. An exploit could allow the attacker to bypass filtering and deliver malicious requests to protected systems that would otherwise be blocked. Once the initial protocol flow on the nonstandard port is detected, future flows on the nonstandard port will be successfully detected and handled as configured by the applied policy.
CVE-2026-23813 1 Hpe 156 Aruba Cx 10000-48y6c \(r8p13a\), Aruba Cx 10000-48y6c \(r8p14a\), Aruba Cx 10000-48y6c \(s0f98a\) and 153 more 2026-08-11 N/A 9.8 CRITICAL
A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.
CVE-2026-23600 1 Hpe 1 Autopass License Server 2026-08-10 N/A 9.8 CRITICAL
A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).
CVE-2026-16232 1 Checkpoint 2 Multi-domain Security Management, Quantum Security Management 2026-08-10 N/A 9.8 CRITICAL
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
CVE-2024-38225 1 Microsoft 1 Dynamics 365 Business Central 2026-08-10 N/A 8.8 HIGH
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2021-36949 1 Microsoft 2 Azure Active Directory Connect, Azure Active Directory Connect Provisioning Agent 2026-08-10 4.9 MEDIUM 7.1 HIGH
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
CVE-2026-12183 2026-08-10 N/A 9.8 CRITICAL
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.
CVE-2026-18651 1 Redhat 3 389 Directory Server, Directory Server, Enterprise Linux 2026-08-09 N/A 5.4 MEDIUM
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control.
CVE-2026-56793 1 Dell 1 Openmanage Server Administrator 2026-08-08 N/A 7.7 HIGH
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-56162 1 Microsoft 1 Azure Sql Database 2026-08-08 N/A 10.0 CRITICAL
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-14541 1 Google 1 Mcp Toolbox For Databases 2026-08-08 N/A 7.5 HIGH
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips audience validation entirely. As a result, the toolbox will accept any valid Google OAuth access token—even those minted for unrelated ecosystem applications—granting unauthorized clients access to protected tools and data backends.
CVE-2026-60678 1 Oracle 1 E-business Suite 2026-08-07 N/A 8.8 HIGH
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in takeover of Oracle General Ledger. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2026-62825 1 Microsoft 1 Azure Key Vault 2026-08-07 N/A 10.0 CRITICAL
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62896 1 Microsoft 1 Teams 2026-08-07 N/A 9.6 CRITICAL
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.