Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TY
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affect
A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create
In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifi
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_pa
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase a
Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This i
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in a
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploite
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth()
authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 al
Windows Netlogon Elevation of Privilege Vulnerability
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters a
CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration o
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctl
Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter`
An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attacker
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing
ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attack
Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to
Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n
Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege
An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated ch
Sensitive information disclosure in NetScaler Console
The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verificatio
Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerabilit
The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend M
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. all
DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication v
A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from
Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox
Windows Task Scheduler Elevation of Privilege Vulnerability
NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper au
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the impleme
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet
Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their ow
Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerabilit
In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Cred
There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS version
Initial xbl_sec revision does not have all the debug policy features and critical checks.
An image with a version lower than the fuse version may potentially be booted lead to improper authentication.
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass a
The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnera
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started