A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and proces
OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From vers
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may
Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWT
Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) managem
Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in
Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authenticatio
Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorre
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerabil
MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP s
The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 t
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementati
Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incomin
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulne
The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution T
An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7.
Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate a
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in version
Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requ
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe usin
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electron
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentic
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and ab
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that
Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions th
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerabili
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor
Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GA
An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an a
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to auth
An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage
Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequest
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actu
VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be ab
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). The supported versi
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started