Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-287

MITRE ↗

Improper Authentication

1,116
CRITICAL
1,386
HIGH
1,045
MEDIUM
94
LOW
3,718 CVEs · Page 47/75
9.8
CVE-2021-24527

The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to rese

9.8
CVE-2021-37597

WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.

9.8
CVE-2021-32967

Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without bein

9.8
CVE-2021-37417

Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.

9.8
CVE-2021-34578

This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by s

9.8
CVE-2021-22002

VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be a

9.8
CVE-2021-40350

webctrl.cgi.elf on Christie Digital DWU850-GS V06.46 devices allows attackers to perform any desired action via a crafte

9.8
CVE-2021-34746

A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infras

9.8
CVE-2021-33044 KEV

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by

9.8
CVE-2021-33045 KEV

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by

9.8
CVE-2021-41303

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authe

9.8
CVE-2021-41317

XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.

9.8
CVE-2021-31917

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An atta

9.8
CVE-2021-22869

An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted

9.8
CVE-2021-38299

Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to

9.8
CVE-2021-35943

Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented

9.8
CVE-2021-41292

ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie pois

9.8
CVE-2021-20578

IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized

9.8
CVE-2021-35296

An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via m

9.8
CVE-2021-39226 KEV

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are

9.8
CVE-2021-37123

There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when

9.8
CVE-2021-31349

The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to v

9.8
CVE-2021-42837

An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not c

9.8
CVE-2021-37580

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass a

9.8
CVE-2021-42338

4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to byp

9.8
CVE-2021-43786

Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verific

9.8
CVE-2021-43931

The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result

9.8
CVE-2021-41716

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeov

9.8
CVE-2021-44514

OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.

9.8
CVE-2021-44524

A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), S

9.8
CVE-2021-4073

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including

9.8
CVE-2021-44675

Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution du

9.8
CVE-2021-44676

Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control detail

9.8
CVE-2021-44525

Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a fi

9.8
CVE-2021-21952

An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security b

9.8
CVE-2021-45890

basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.

9.6
CVE-2021-21538

Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability

9.6
CVE-2021-22943

A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained

9.6
CVE-2021-28494

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditio

9.6
CVE-2021-38412

Properly formatted POST requests to multiple resources on the HTTP and HTTPS web servers of the Digi PortServer TS 16 Ra

9.1
CVE-2020-28050

Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to co

9.1
CVE-2021-21982

VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a

9.1
CVE-2021-21399

Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated

9.1
CVE-2020-11264

Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packe

9.1
CVE-2020-11301

Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosur

9.1
CVE-2021-43834

eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh

8.8
CVE-2021-25863

Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.

8.8
CVE-2020-27865

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1

8.8
CVE-2020-27866

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6020

8.8
CVE-2021-22858

Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrar

Frequently Asked Questions

What is CWE-287?

CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-287?

There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.

How can I protect against CWE-287 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.

Detect CWE-287 Vulnerabilities

CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.

Get Started