Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-287 · Improper authenticationDefinition on MITRE ↗Clear

42 results

CVE-2026-65400
2026-08-18
Apple macOS Improper Authentication Vulnerability
Apple

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.

CWE-287 · Improper authentication
Refssupport.apple.comsupport.apple.comsupport.apple.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-21
CVE-2026-16232
2026-07-22
Check Point SmartConsole Improper Authentication Vulnerability
Check Point

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CWE-287 · Improper authentication
Refssupport.checkpoint.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-25
CVE-2026-46817
2026-07-15
Oracle E-Business Suite Improper Privilege Management Vulnerability
Oracle

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

CWE-269 · Improper privilege managementCWE-287 · Improper authenticationCWE-306 · Missing authentication
Refsoracle.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-18
CVE-2026-50751
2026-06-08
Check Point Security Gateway Improper Authentication VulnerabilityRansomware
Check Point

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CWE-287 · Improper authentication
Refsblog.checkpoint.comsupport.checkpoint.comnvd.nist.gov
Federal remediation due 2026-06-11
CVE-2022-0492
2026-06-02
Linux Kernel Improper Authentication Vulnerability
Linux

Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.

CWE-287 · Improper authenticationCWE-862 · Missing authorization
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seekernel.orgnvd.nist.gov
Federal remediation due 2026-06-05
CVE-2026-20182
2026-05-14
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Cisco

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

CWE-287 · Improper authentication
RefsCISA Mitigation Instructionscisa.govsec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2026-05-17
CVE-2025-32975
2026-04-20
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Quest

Quest KACE Systems Management Appliance (SMA) contains an improper authentication vulnerability that could allow attackers to impersonate legitimate users without valid credentials.

CWE-287 · Improper authentication
Refssupport.quest.comnvd.nist.gov
Federal remediation due 2026-05-04
CVE-2023-27351
2026-04-20
PaperCut NG/MF Improper Authentication VulnerabilityRansomware
PaperCut

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

CWE-287 · Improper authentication
Refspapercut.comnvd.nist.gov
Federal remediation due 2026-05-04
CVE-2017-7921
2026-03-05
Hikvision Multiple Products Improper Authentication Vulnerability
Hikvision

Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.

CWE-287 · Improper authentication
Refshikvision.comnvd.nist.gov
Federal remediation due 2026-03-26
CVE-2026-20127
2026-02-25
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
Cisco

Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

CWE-287 · Improper authentication
RefsCISA Mitigation Instructionscisa.govsec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2026-02-27
CVE-2019-19006
2026-02-03
Sangoma FreePBX Improper Authentication Vulnerability
Sangoma

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.

CWE-287 · Improper authentication
Refswiki.freepbx.orgnvd.nist.gov
Federal remediation due 2026-02-24
CVE-2016-7836
2025-10-14
SKYSEA Client View Improper Authentication Vulnerability
SKYSEA

SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

CWE-287 · Improper authentication
Refsskyseaclientview.netnvd.nist.gov
Federal remediation due 2025-11-04
CVE-2015-7755
2025-10-02
Juniper ScreenOS Improper Authentication Vulnerability
Juniper

Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device.

CWE-287 · Improper authentication
Refssupportportal.juniper.netnvd.nist.gov
Federal remediation due 2025-10-23
CVE-2025-49706
2025-07-22
Microsoft SharePoint Improper Authentication VulnerabilityRansomware
Microsoft

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.

CWE-287 · Improper authentication
RefsCISA Mitigation Instructionsmicrosoft.commsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-07-23
CVE-2025-3935
2025-06-02
ConnectWise ScreenConnect Improper Authentication Vulnerability
ConnectWise

ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys are compromised.

CWE-287 · Improper authentication
Refsconnectwise.comnvd.nist.gov
Federal remediation due 2025-06-23
CVE-2021-32030
2025-06-02
ASUS Routers Improper Authentication Vulnerability
ASUS

ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-287 · Improper authentication
Refsasus.comasus.comnvd.nist.gov
Federal remediation due 2025-06-23
CVE-2024-53704
2025-02-18
SonicWall SonicOS SSLVPN Improper Authentication VulnerabilityRansomware
SonicWall

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

CWE-287 · Improper authentication
Refspsirt.global.sonicwall.comnvd.nist.gov
Federal remediation due 2025-03-11
CVE-2024-11680
2024-12-03
ProjectSend Improper Authentication Vulnerability
ProjectSend

ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Successful exploitation allows attackers to create accounts, upload webshells, and embed malicious JavaScript.

CWE-287 · Improper authentication
Refsgithub.comnvd.nist.gov
Federal remediation due 2024-12-24
CVE-2024-49039
2024-11-12
Microsoft Windows Task Scheduler Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.

CWE-287 · Improper authentication
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-12-03
CVE-2024-8956
2024-11-04
PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability
PTZOptics

PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If combined with CVE-2024-8957, this can lead to remote code execution as root.

CWE-287 · Improper authentication
Refsptzoptics.comnvd.nist.gov
Federal remediation due 2024-11-25
CVE-2024-7593
2024-09-24
Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
Ivanti

Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.

CWE-287 · Improper authenticationCWE-303
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2024-10-15
CVE-2021-33045
2024-08-21
Dahua IP Camera Authentication Bypass Vulnerability
Dahua / IP Camera Firmware

Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.

CWE-287 · Improper authentication
Refsdahuasecurity.comnvd.nist.gov
Federal remediation due 2024-09-11
CVE-2021-33044
2024-08-21
Dahua IP Camera Authentication Bypass Vulnerability
Dahua / IP Camera Firmware

Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.

CWE-287 · Improper authentication
Refsdahuasecurity.comnvd.nist.gov
Federal remediation due 2024-09-11
CVE-2024-21410
2024-02-15
Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.

CWE-287 · Improper authentication
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2024-03-07
CVE-2023-35082
2024-01-18
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass VulnerabilityRansomware
Ivanti

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.

CWE-287 · Improper authentication
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2024-02-08
CVE-2023-46805
2024-01-10
Ivanti Connect Secure and Policy Secure Authentication Bypass VulnerabilityRansomware
Ivanti

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

CWE-287 · Improper authentication
RefsPlease apply mitigations per vendor instructions. For more information, please seenvd.nist.gov
Federal remediation due 2024-01-22
CVE-2023-35078
2023-07-25
Ivanti Endpoint Manager Mobile Authentication Bypass VulnerabilityRansomware
Ivanti / Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.

CWE-287 · Improper authentication
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2023-08-15
CVE-2023-20867
2023-06-23
VMware Tools Authentication Bypass Vulnerability
VMware

VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. An attacker must have root access over ESXi to exploit this vulnerability.

CWE-287 · Improper authentication
Refsvmware.comnvd.nist.gov
Federal remediation due 2023-07-14
CVE-2021-27878
2023-04-07
Veritas Backup Exec Agent Command Execution VulnerabilityRansomware
Veritas

Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.

CWE-287 · Improper authentication
Refsveritas.comnvd.nist.gov
Federal remediation due 2023-04-28
CVE-2021-27877
2023-04-07
Veritas Backup Exec Agent Improper Authentication VulnerabilityRansomware
Veritas

Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.

CWE-287 · Improper authentication
Refsveritas.comnvd.nist.gov
Federal remediation due 2023-04-28
CVE-2021-27876
2023-04-07
Veritas Backup Exec Agent File Access VulnerabilityRansomware
Veritas

Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.

CWE-287 · Improper authentication
Refsveritas.comnvd.nist.gov
Federal remediation due 2023-04-28
CVE-2021-39226
2022-08-25
Grafana Authentication Bypass Vulnerability
Grafana Labs

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.

CWE-287 · Improper authentication
Refsgrafana.comnvd.nist.gov
Federal remediation due 2022-09-15
CVE-2018-10561
2022-03-31
Dasan GPON Routers Authentication Bypass Vulnerability
Dasan / Gigabit Passive Optical Network (GPON) Routers

Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-04-21
CVE-2015-1187
2022-03-25
D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability
D-Link and TRENDnet

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2019-0543
2022-03-15
Microsoft Windows Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2021-33766
2022-01-18
Microsoft Exchange Server Information Disclosure
Microsoft

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-32648
2022-01-18
October CMS Improper Authentication
October CMS

In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-02-01
CVE-2021-34523
2021-11-03
Microsoft Exchange Server Privilege Escalation VulnerabilityRansomware
Microsoft

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-22893
2021-11-03
Ivanti Pulse Connect Secure Use-After-Free VulnerabilityRansomware
Ivanti

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

CWE-287 · Improper authentication
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2020-5849
2021-11-03
Unraid Authentication Bypass Vulnerability
Unraid

Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.

CWE-287 · Improper authenticationCWE-697
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-12812
2021-11-03
Fortinet FortiOS SSL VPN Improper Authentication VulnerabilityRansomware
Fortinet

Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.

CWE-178CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2020-0688
2021-11-03
Microsoft Exchange Server Validation Key Remote Code Execution VulnerabilityRansomware
Microsoft

Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.

CWE-287 · Improper authentication
Refsnvd.nist.gov
Federal remediation due 2022-05-03