Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentica
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui
An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v
OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to ver
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates
Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to i
The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported ver
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and dire
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructu
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Qua
Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp
Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supp
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Repor
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve
Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Intern
Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operation
Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Intern
Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Intern
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to prot
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versio
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install). The support
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management).
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Support
Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Pricing Installation). Supp
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supporte
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Labor Distribution product of Oracle E-Business Suite (component: Internal Operations). Sup
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Advanced Collections product of Oracle E-Business Suite (component: Internal Operations). S
Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operat
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started