A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected
A vulnerability in NetBatch-Plus software allows unauthorized access to the application. HPE has provided a workaround
A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chro
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authenticat
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can g
Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user
SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account)
A vulnerability has been identified in SICAM GridEdge (Classic) (All versions < V2.6.6). The affected application does n
An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system informat
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, th
An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, th
In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, The
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/fi
There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions p
An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow
Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated
There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vuln
Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.
Prior Dell BIOS versions contain an Improper Authentication vulnerability. An unauthenticated attacker with physical acc
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By ex
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with ph
`@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.
Improper authentication in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a pri
An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.
An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20
An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this v
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause impr
Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configur
Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without
A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Tim
A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/Zy
A vulnerability classified as critical was found in Telecommunication Software SAMwin Contact Center Suite 5.1. This vul
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jen
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node
Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly
An authentication bypass risk was identified in the external database authentication functionality, due to a type juggli
An issue has been discovered in GitLab affecting all versions starting from 12.10 before 15.1.6, all versions starting f
An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-b
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1
Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a use
There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the a
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started