A vulnerability was detected in badlogic pi-mono up to 0.58.4. This issue affects some unknown processing of the file pa
HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated
A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function
A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of t
A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setti
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, a
A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_se
SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clau
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all
A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/servi
Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer au
Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing en
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request
An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more tha
Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the au
A weakness has been identified in CRMEB up to 5.6.3. The impacted element is the function remoteRegister of the file crm
A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of th
A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the
A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of t
A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check
A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of th
A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown func
A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of th
A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordA
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web
A security flaw has been discovered in treefrogframework treefrog-framework up to 2.11.2. This vulnerability affects the
A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of t
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5
SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerp
XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts coul
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file m
Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an
X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, al
A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO)
The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and s
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started