Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge). Th
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: In
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Re
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integratio
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote at
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, a
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it be
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allo
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenti
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing u
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the S
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-veri
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 th
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensit
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the functio
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accep
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Suppo
The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper auth
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authen
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauth
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' param
A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated at
Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) c
ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The
Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asser
Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affe
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions up to and inc
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l
A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.
An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any u
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control e
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started