Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leadi
BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentic
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially e
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supp
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9. A us
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (p
IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A loca
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to o
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, th
Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prio
The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause u
CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on A
Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-al
A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component P
jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to
Session 1.13.0 allows an attacker with physical access to the victim's device to bypass the application's password/pin l
A lock screen issue was addressed with improved state management. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, i
Improper authentication in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel
Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated t
Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without ha
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not valid
Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to b
An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 befor
Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.
Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.
Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14
Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially e
Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devic
Arvados is an open source platform for managing and analyzing biomedical big data. In versions prior to 2.4.3, when usin
Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change
Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut witho
Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locke
Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The pat
A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by una
An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of s
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accesse
A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /ba
A vulnerability was found in Klapp App and classified as problematic. This issue affects some unknown processing of the
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep op
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS
A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Af
Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEG
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started