Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG
The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows
Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affect
Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Cons
Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Bu
Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.T
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability a
YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combinatio
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user do
HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in
Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allo
The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all
The vulnerability could be remotely exploited to bypass authentication.
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker w
Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Auth
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This i
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attac
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.
A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN t
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication v
The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and includi
Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enable
In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to o
Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authe
Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper a
The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including
The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includin
In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this
Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-
An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the
The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerabi
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited,
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultim
JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereb
A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azu
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet
A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messag
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started