CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,934 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 64 of 99
- CVE-2022-37397CRITICALCVSS 8.3EG 9.82022-08-12
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty p…
- CVE-2022-37774MEDIUMCVSS 5.3EG 5.32022-11-23
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 has…
- CVE-2022-37913CRITICALCVSS 9.8EG 9.82022-10-28
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an att…
- CVE-2022-37914CRITICALCVSS 9.8EG 9.82022-10-28
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an att…
- CVE-2022-37931HIGHCVSS 7.3EG 7.82022-11-22
A vulnerability in NetBatch-Plus software allows unauthorized access to the application. HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.
- CVE-2022-37932CRITICALCVSS 8.8EG 9.82022-12-12
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The vulnerability could be remotely exploited to allow authentication bypass. HPE has made the follo…
- CVE-2022-38064MEDIUMCVSS 6.2EG 6.22022-09-09
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
- CVE-2022-38081MEDIUMCVSS 6.2EG 6.22022-09-09
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.
- CVE-2022-38119CRITICALCVSS 9.8EG 9.82022-11-10
UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privilege to access, control system or disrupt service.
- CVE-2022-38180MEDIUMCVSS 5.3EG 5.32022-08-12
In JetBrains Ktor before 2.1.0 the wrong authentication provider could be selected in some cases
- CVE-2022-38336HIGHCVSS 8.1EG 8.12022-12-06
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.
- CVE-2022-38368HIGHCVSS 8.8EG 8.82022-08-15
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.
- CVE-2022-38399MEDIUMCVSS 6.8EG 6.82022-09-08
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's …
- CVE-2022-38556CRITICALCVSS 9.8EG 9.82022-08-28
Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
- CVE-2022-38557CRITICALCVSS 9.8EG 9.82022-08-28
D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
- CVE-2022-38700HIGHCVSS 8.8EG 8.82022-09-09
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.
- CVE-2022-38733HIGHCVSS 8.6EG 8.62022-12-20
OnCommand Insight versions 7.3.1 through 7.3.14 are susceptible to an authentication bypass vulnerability in the Data Warehouse component.
- CVE-2022-38744HIGHCVSS 7.5EG 7.52022-10-27
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a se…
- CVE-2022-3875HIGHCVSS 7.3EG 7.52022-12-19
A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affects unknown code of the component API. The manipulation leads to authentication bypass by as…
- CVE-2022-38753MEDIUMCVSS 6.3EG 6.32022-11-28
This update resolves a multi-factor authentication bypass attack
- CVE-2022-38982CRITICALCVSS 9.8EG 9.82022-10-14
The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.
- CVE-2022-39007CRITICALCVSS 9.8EG 9.82022-09-16
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.
- CVE-2022-39009CRITICALCVSS 9.8EG 9.82022-09-16
The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.
- CVE-2022-39018HIGHCVSS 8.2EG 8.22022-10-31
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
- CVE-2022-39019HIGHCVSS 6.3EG 7.52022-10-31
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
- CVE-2022-39038HIGHCVSS 8.8EG 8.82022-11-10
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt …
- CVE-2022-39042CRITICALCVSS 9.8EG 9.82023-01-03
aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.
- CVE-2022-39184CRITICALCVSS 9.8EG 9.82023-01-12
EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass.
- CVE-2022-39205CRITICALCVSS 9.0EG 9.02022-09-13
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The /git-prereceive-callba…
- CVE-2022-39219HIGHCVSS 8.5EG 8.52022-09-26
Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow grou…
- CVE-2022-39229MEDIUMCVSS 4.3EG 4.32022-10-13
Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafa…
- CVE-2022-39231LOWCVSS 3.7EG 3.72022-09-23
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.16, or from 5.0.0 to 5.2.6, validation of the authentication adapter app ID for _Facebook_ and _Spotify_ may …
- CVE-2022-39238MEDIUMCVSS 4.2EG 4.22022-09-23
Arvados is an open source platform for managing and analyzing biomedical big data. In versions prior to 2.4.3, when using Portable Authentication Modules (PAM) for user authentication, if a user presented valid credentials but the account …
- CVE-2022-39245HIGHCVSS 8.4EG 8.42022-09-26
Mist is the command-line interface for the makedeb Package Repository. Prior to version 0.9.5, a user-provided `sudo` binary via the `PATH` variable can allow a local user to run arbitrary commands on the user's system with root permission…
- CVE-2022-39246HIGHCVSS 7.5EG 7.52022-09-28
matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shie…
- CVE-2022-39248HIGHCVSS 8.6EG 8.62022-09-28
matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as…
- CVE-2022-39249HIGHCVSS 7.5EG 7.52022-09-28
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be mar…
- CVE-2022-39250HIGHCVSS 8.6EG 8.62022-09-29
Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, inj…
- CVE-2022-39251HIGHCVSS 8.6EG 8.62022-09-28
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without an…
- CVE-2022-39252HIGHCVSS 8.6EG 8.62022-09-29
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly rememb…
- CVE-2022-39254HIGHCVSS 8.6EG 8.62022-09-29
matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a users requests a room key from their devices, the software correctly remember the request. Once they receive a forwarded…
- CVE-2022-39255HIGHCVSS 8.6EG 8.62022-09-28
Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, with…
- CVE-2022-39257HIGHCVSS 7.5EG 7.52022-09-28
Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will …
- CVE-2022-39263MEDIUMCVSS 6.8EG 6.82022-09-28
`@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.js. Applications that use `next-auth` Email Provider and `@next-auth/upstash-redis-adapter` before v3.0.2 are affected …
- CVE-2022-39264HIGHCVSS 8.6EG 8.62022-09-28
nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to pro…
- CVE-2022-39267HIGHCVSS 8.8EG 8.82022-10-19
Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environments. Versions prior to 1.8.8-release are subject to authentication bypass in the admin a…
- CVE-2022-39289CRITICALCVSS 9.1EG 9.12022-10-07
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without Sy…
- CVE-2022-39290HIGHCVSS 8.0EG 8.02022-10-07
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application. These modifications includ…
- CVE-2022-39355CRITICALCVSS 9.1EG 9.12022-10-26
Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabled, an improper authentication vulnerability could be used to take control of a victim's forum account. This vulnerabil…
- CVE-2022-39360MEDIUMCVSS 6.5EG 6.52022-10-26
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a user access without g…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →