An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentica
Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properl
Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not P
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur und
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to ac
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Cons
Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render sec
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would al
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Tra
The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the
In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Ca
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in link
A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulner
Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the fil
The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Pro
A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to
Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionalit
An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to imp
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensiti
Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OA
Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.
Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Authentication vul
Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.2
A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown cod
IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow a remote attacker to bypass a
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A loc
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of
Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Start
Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise
SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on
When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. Th
IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when co
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploite
Improper Authentication vulnerability in Apache Ozone. The vulnerability allows an attacker to download metadata intern
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device
Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n
REST service authentication anomaly with “valid username/no password” credential combination for batch job processing re
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG
Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabil
An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An
Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda en
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started