CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,933 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 63 of 99
- CVE-2022-34446HIGHCVSS 8.8EG 8.82023-02-11
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive infor…
- CVE-2022-34535HIGHCVSS 7.5EG 7.52022-07-19
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
- CVE-2022-34575MEDIUMCVSS 5.7EG 5.72022-07-25
An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key information of the device via accessing fctest.shtml.
- CVE-2022-3465CRITICALCVSS 7.3EG 9.82022-10-12
A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of the file /index.asp. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit…
- CVE-2022-34767CRITICALCVSS 5.9EG 9.82022-07-21
Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the password, located at "admin" allows changing the http[s]://wizardpwd.asp/cgi-bin. Does not validate the user's identity and …
- CVE-2022-3477CRITICALCVSS 9.8EG 9.82022-11-14
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to …
- CVE-2022-34839CRITICALCVSS 5.9EG 9.82022-07-22
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.
- CVE-2022-34858CRITICALCVSS 9.8EG 9.82022-08-22
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
- CVE-2022-34887MEDIUMCVSS 4.3EG 4.32023-10-27
Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers without having to authenticate with the administrator password.
- CVE-2022-34907CRITICALCVSS 9.8EG 9.82022-07-25
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over…
- CVE-2022-34908HIGHCVSS 8.2EG 8.22023-02-27
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple H…
- CVE-2022-34919CRITICALCVSS 9.8EG 9.82022-08-23
The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.
- CVE-2022-35122CRITICALCVSS 9.1EG 9.12022-08-17
An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information including device and local WiFi passwords.
- CVE-2022-35135HIGHCVSS 8.8EG 8.82022-10-13
Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>.
- CVE-2022-35142HIGHCVSS 7.5EG 7.52022-08-04
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the Search parameter.
- CVE-2022-35147CRITICALCVSS 9.8EG 9.82022-08-17
DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
- CVE-2022-35167HIGHCVSS 8.8EG 8.82022-08-19
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
- CVE-2022-35198HIGHCVSS 7.5EG 7.52022-08-18
Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.
- CVE-2022-35203HIGHCVSS 7.2EG 7.22022-08-23
An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system information.
- CVE-2022-35248HIGHCVSS 8.8EG 8.82022-09-23
A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypassed when telling the server to use CAS during login.
- CVE-2022-35401HIGHCVSS 8.1EG 8.12023-01-10
An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would ne…
- CVE-2022-35629MEDIUMCVSS 5.4EG 5.42022-07-29
Due to a bug in the handling of the communication between the client and server, it was possible for one client, already registered with their own client ID, to send messages to the server claiming to come from another client ID. This issu…
- CVE-2022-35646MEDIUMCVSS 5.9EG 5.92022-12-22
IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096.
- CVE-2022-35726CRITICALCVSS 4.3EG 9.82022-08-23
Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress.
- CVE-2022-35843CRITICALCVSS 8.1EG 9.82022-12-06
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 th…
- CVE-2022-35898CRITICALCVSS 9.8EG 9.82023-05-01
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.
- CVE-2022-35925MEDIUMCVSS 5.3EG 5.32022-08-02
BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentication views which allows brute-force attacks. This issue has been patched in version 0.4.5. Admins with existing instan…
- CVE-2022-36071HIGHCVSS 8.3EG 8.32022-09-02
SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based One Time Passwords) as a secondary authentication factor. Because TOTPs are often configu…
- CVE-2022-36073HIGHCVSS 8.3EG 8.32022-09-07
RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to change their RubyGems.org account's email to an unowned email address. Having access to an account whose email has been …
- CVE-2022-36092HIGHCVSS 7.5EG 7.52022-09-08
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.4, all rights checks that would normally prevent a user from viewing a document on a wiki can be bypassed using the log…
- CVE-2022-36093HIGHCVSS 8.5EG 8.52022-09-08
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart template, user accounts can be created even when user registration is disabled. This also…
- CVE-2022-36106MEDIUMCVSS 5.4EG 5.42022-09-13
TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that the expiration time of a password reset link for TYPO3 backend users has never been evaluated. As a result, a password …
- CVE-2022-36133CRITICALCVSS 9.1EG 9.12022-11-25
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.
- CVE-2022-36296MEDIUMCVSS 6.5EG 6.52022-08-05
Broken Authentication vulnerability in JumpDEMAND Inc. ActiveDEMAND plugin <= 0.2.27 at WordPress allows unauthenticated post update/create/delete.
- CVE-2022-36370HIGHCVSS 7.5EG 7.82022-11-11
Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2022-36412CRITICALCVSS 9.8EG 9.82022-07-26
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
- CVE-2022-36436CRITICALCVSS 9.8EG 9.82022-09-14
OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability that could allow a malicious actor to gain unauthorized access to a VNC session or to disconn…
- CVE-2022-36524HIGHCVSS 7.5EG 7.52022-08-15
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /etc/init0.d/S80telnetd.sh.
- CVE-2022-36526HIGHCVSS 7.5EG 7.52022-08-15
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via function phpcgi_main in cgibin.
- CVE-2022-3674CRITICALCVSS 7.3EG 9.82022-10-26
A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be…
- CVE-2022-36755CRITICALCVSS 9.8EG 9.82022-08-28
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
- CVE-2022-36774MEDIUMCVSS 5.3EG 5.32022-10-06
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575.
- CVE-2022-3681MEDIUMCVSS 6.5EG 6.52023-10-27
A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wire…
- CVE-2022-36960HIGHCVSS 8.8EG 8.82022-11-29
SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.
- CVE-2022-37026CRITICALCVSS 9.8EG 9.82022-09-21
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.
- CVE-2022-37042CRITICALCVSS 9.8EG 9.8⚠ KEV2022-08-12
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the…
- CVE-2022-37163CRITICALCVSS 9.8EG 9.82022-09-08
Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making …
- CVE-2022-37164CRITICALCVSS 9.8EG 9.82022-09-08
Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much ea…
- CVE-2022-37298CRITICALCVSS 9.8EG 9.82022-10-20
Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from mo…
- CVE-2022-37345HIGHCVSS 7.8EG 7.82022-11-11
Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable escalation of privilege via local access.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →