matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 t
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT
Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffo
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to ins
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unau
A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco B
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote u
Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to att
Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior
PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerabil
EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication
Improper Authentication in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
TP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerabil
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the
An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a craf
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a
An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.
Netgear RAX30 (AX2400), prior to version 1.0.6.74, was affected by an authentication bypass vulnerability, allowing an u
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the
api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.
Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication,
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 bu
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrec
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug func
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur und
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML User
Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication B
Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication
The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows
Improper Authentication vulnerability in Easy Digital Downloads plugin allows unauth. Privilege Escalation. This issue a
An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authenticati
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This is
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid cr
The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.
Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauth
Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.
An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges
Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an
Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo:
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started