Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-287

MITRE ↗

Improper Authentication

1,116
CRITICAL
1,386
HIGH
1,045
MEDIUM
94
LOW
3,718 CVEs · Page 19/75
8.1
CVE-2025-27086

A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.

8.1
CVE-2024-11917

The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ

8.1
CVE-2025-22236

Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to

8.1
CVE-2025-6763

A vulnerability was found in Comet System T0510, T3510, T3511, T4511, T6640, T7511, T7611, P8510, P8552 and H3531 1.60.

8.1
CVE-2025-6505

Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipe

8.1
CVE-2024-50641

An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnera

8.1
CVE-2025-20160

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allo

8.1
CVE-2025-62169

OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of th

8.1
CVE-2025-67507

Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 cont

8.1
CVE-2025-14002

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass via brute force in all versions up to, and

8.0
CVE-2025-53786

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-sec

8.0
CVE-2025-58060

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12

8.0
CVE-2025-54761

An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.

7.8
CVE-2025-0217

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A loc

7.8
CVE-2024-13088

An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, t

7.8
CVE-2025-41459

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App St

7.8
CVE-2025-9815

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function o

7.8
CVE-2025-10672

A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIB

7.8
CVE-2025-43281

The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be

7.7
CVE-2025-2230

A flaw exists in the Windows login flow where an AuthContext token can be exploited for replay attacks and authenticati

7.7
CVE-2024-57490

Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system

7.7
CVE-2025-61679

Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained

7.6
CVE-2025-53169

Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful e

7.6
CVE-2025-60424

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to byp

7.5
CVE-2025-21618

NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for

7.5
CVE-2024-11322

A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote atta

7.5
CVE-2024-57432

macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do no

7.5
CVE-2024-13528

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versi

7.5
CVE-2025-27422

FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker regis

7.5
CVE-2025-30116

An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Liv

7.5
CVE-2025-30214

Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could l

7.5
CVE-2025-25227

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

7.5
CVE-2025-20083

Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enab

7.5
CVE-2025-53793

Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.

7.5
CVE-2025-55171

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio

7.5
CVE-2025-54376

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v

7.5
CVE-2025-31271

This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime cal

7.5
CVE-2025-61665

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken

7.5
CVE-2025-61884 KEV

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions

7.5
CVE-2024-21635

Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. Wh

7.5
CVE-2025-14738

Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download th

7.4
CVE-2025-22228

BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters

7.4
CVE-2025-49812

In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows

7.3
CVE-2025-1104

A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown

7.3
CVE-2025-2388

A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by this vulnerability is

7.3
CVE-2025-4019

A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af447

7.3
CVE-2025-4494

A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin

7.3
CVE-2025-4755

A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been classified as critical. This affects the

7.3
CVE-2025-5247

A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function

7.3
CVE-2025-5495

A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknow

Frequently Asked Questions

What is CWE-287?

CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-287?

There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.

How can I protect against CWE-287 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.

Detect CWE-287 Vulnerabilities

CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.

Get Started