Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication
The Japanized for WooCommerce plugin for WordPress is vulnerable to Improper Authentication in versions up to, and inclu
OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in
Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talis
A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea
Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before t
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to,
A vulnerability was detected in PrefectHQ prefect up to 3.6.21. This impacts the function endswith of the file /api/heal
A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown func
A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. This affects the function doAction of
A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function
A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publ
Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are rec
ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthent
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthro
CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authe
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.1
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of th
The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint T
Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as
The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, all
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-
A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.asp
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t
The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against t
An unauthenticated user may bypass authentication under specific cache conditions.
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due t
The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually bee
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the
A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerabili
A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown fun
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to
A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in ver
Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulne
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 't
capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSuc
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configu
The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica
A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of th
Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlockin
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started