A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknow
A vulnerability has been found in TRENDnet TV-IP121W 1.1.1 Build 36 and classified as critical. Affected by this vulnera
A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part
A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this i
A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as cri
A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as cr
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnera
A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This affects an unknown part
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue
Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue
A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability
A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /form
In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the ba
A vulnerability was identified in samanhappy MCPHub up to 0.9.10. This vulnerability affects the function handleSseConne
A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/
A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59
A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing
A vulnerability was found in Alteryx Server. Affected by this issue is some unknown functionality of the file /gallery/a
A vulnerability was identified in simstudioai sim up to 0.5.27. This vulnerability affects unknown code of the file apps
An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privile
A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthor
Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect s
Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3
Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature lo
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 a
Windows Remote Desktop Configuration Service Tampering Vulnerability
CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized use
The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An
An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Bio
A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VP
A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Ada
An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical a
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica
If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. T
An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to Ma
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local esc
A user with administrator privileges is able to retrieve authentication tokens
Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.
Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.
Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulner
Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to vers
In JotUrl 2.0, is possible to bypass security requirements during the password change process.
Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote
An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started