CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,933 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 58 of 99
- CVE-2022-1148MEDIUMCVSS 5.3EG 6.52022-04-04
Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled…
- CVE-2022-1248HIGHCVSS 7.3EG 7.32022-04-06
A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the file /SAP_Information_System/controllers/add_admin.php. An unauthenticated attacker is able to create a new admin accou…
- CVE-2022-1349MEDIUMCVSS 4.3EG 4.32022-05-16
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to the image_id parameter of the ajax action wpqa_remove_image belongs to the requesting user…
- CVE-2022-1426LOWCVSS 2.0EG 3.72022-05-11
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user …
- CVE-2022-1460MEDIUMCVSS 6.1EG 6.12022-05-11
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations…
- CVE-2022-1681HIGHCVSS 7.2EG 7.22022-05-12
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions
- CVE-2022-1716MEDIUMCVSS 4.6EG 4.62022-06-02
Keep My Notes v1.80.147 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code ma…
- CVE-2022-1801HIGHCVSS 7.5EG 7.52022-06-20
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check…
- CVE-2022-1955MEDIUMCVSS 4.6EG 4.62022-06-30
Session 1.13.0 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulatio…
- CVE-2022-20126HIGHCVSS 7.3EG 7.32022-06-15
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges n…
- CVE-2022-2031HIGHCVSS 8.8EG 8.82022-08-25
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets. A user who has been requested to change their password, ca…
- CVE-2022-20662MEDIUMCVSS 6.1EG 6.82022-09-30
A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker with physical access to bypass authentication. This vulnerability exists because the assigned user of a smart card is not…
- CVE-2022-20695CRITICALCVSS 10.0EG 10.02022-04-15
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface…
- CVE-2022-20733CRITICALCVSS 5.3EG 9.82022-06-15
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sen…
- CVE-2022-20798CRITICALCVSS 9.8EG 9.82022-06-15
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remot…
- CVE-2022-2083HIGHCVSS 7.5EG 7.52022-09-05
The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers to gain unauthorized access to the site.
- CVE-2022-20918HIGHCVSS 7.5EG 7.52022-11-15
A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generati…
- CVE-2022-20923CRITICALCVSS 4.0EG 9.82022-09-08
A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to bypass authentication controls and access the IPSec V…
- CVE-2022-21142CRITICALCVSS 9.8EG 9.82022-02-24
Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to Ver.2.10.43, and Ver.2.11.x series versions prior to Ver.2.…
- CVE-2022-21196CRITICALCVSS 10.0EG 10.02022-02-18
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An att…
- CVE-2022-2133MEDIUMCVSS 5.3EG 5.32022-07-17
The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate, which allows attackers to log onto the site with the only knowledge of a user's email address.
- CVE-2022-2141CRITICALCVSS 9.8EG 9.82022-07-20
SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.
- CVE-2022-21618MEDIUMCVSS 5.3EG 5.32022-10-18
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 21.3.3 and 22.2.0…
- CVE-2022-21684MEDIUMCVSS 4.3EG 4.32022-01-13
Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0.beta11 in `tests-passed` allow some users to log in to a community before they should be able to do so. A user invited…
- CVE-2022-21692MEDIUMCVSS 4.3EG 4.32022-01-18
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised …
- CVE-2022-21695MEDIUMCVSS 4.3EG 4.32022-01-18
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated users (or unauthenticated in public mode) can send message…
- CVE-2022-21794HIGHCVSS 7.7EG 7.72022-11-11
Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via lo…
- CVE-2022-21934HIGHCVSS 8.0EG 8.82022-05-06
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.
- CVE-2022-21935HIGHCVSS 7.5EG 7.52022-06-15
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.
- CVE-2022-21936HIGHCVSS 8.1EG 8.12022-10-07
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
- CVE-2022-21968MEDIUMCVSS 4.3EG 4.32022-02-09
Microsoft SharePoint Server Security Feature Bypass Vulnerability
- CVE-2022-2197CRITICALCVSS 9.8EG 9.82022-06-30
By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and perform administrative operations.
- CVE-2022-22237MEDIUMCVSS 6.5EG 6.52022-10-18
An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity. A vulnerability in the processing of TCP-AO will allo…
- CVE-2022-22259MEDIUMCVSS 6.8EG 6.82022-06-13
There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vulnerability may lead to a control of the victim device.
- CVE-2022-22279MEDIUMCVSS 4.9EG 4.92022-04-13
A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.…
- CVE-2022-22283LOWCVSS 2.8EG 2.82022-01-10
Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.
- CVE-2022-22284MEDIUMCVSS 5.7EG 5.72022-01-10
Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication
- CVE-2022-22289MEDIUMCVSS 5.3EG 5.32022-01-10
Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.
- CVE-2022-22426LOWCVSS 3.3EG 3.32022-06-10
IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication restrictions, caused by the lack of proper session management. An attacker could exploit this vulnerability to bypass au…
- CVE-2022-22485CRITICALCVSS 9.8EG 9.82022-06-17
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attack…
- CVE-2022-22487CRITICALCVSS 9.8EG 9.82022-06-30
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vu…
- CVE-2022-22523HIGHCVSS 7.5EG 7.52022-09-28
An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 Web-App which allows an authentication bypass to the context of an unauthorised user if free-access i…
- CVE-2022-22557HIGHCVSS 7.5EG 7.82022-06-02
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of…
- CVE-2022-22576HIGHCVSS 8.1EG 8.12022-05-26
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as…
- CVE-2022-22656LOWCVSS 3.3EG 3.32022-03-18
An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A local attacker may be able to view the previous logged in user’s…
- CVE-2022-22729HIGHCVSS 8.8EG 8.82022-03-11
CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets. The authentication may be bypassed via some crafted packets: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM…
- CVE-2022-22730CRITICALCVSS 9.8EG 9.82022-08-18
Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
- CVE-2022-22796CRITICALCVSS 7.0EG 9.82022-05-12
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authent…
- CVE-2022-22831CRITICALCVSS 9.8EG 9.82022-02-06
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header.
- CVE-2022-22935LOWCVSS 3.7EG 3.72022-03-29
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of service can cause a MiTM attacker to force a minion process to stop by impersonating a master.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →