Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported version
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions th
Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Solut
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Pr
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffin
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported
Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported ver
Vulnerability in the TeleSales product of Oracle E-Business Suite (component: Internal Operations). Supported versions
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versi
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Sup
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Suppo
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific condi
The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the
The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a networ
Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applicati
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account tak
The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing t
NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by comm
authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2
Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that all
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in
An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to var
authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S
PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated atta
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthen
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users wit
Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote prof
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th
9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* acce
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti
Frequently Asked Questions
What is CWE-287?
CWE-287 (Improper Authentication) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-287?
There are 5,272 CVE records associated with CWE-287 in our database. Of these, 1116 are critical severity, 1386 are high severity, and 1045 are medium severity.
How can I protect against CWE-287 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-287 using AI-powered security agents.
Detect CWE-287 Vulnerabilities
CyberStrike's AI agents automatically detect improper authentication vulnerabilities across your infrastructure.
Get Started