CWE-287— Improper Authentication
4,314 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 64 of 87
- CVE-2023-27261MEDIUMCVSS 5.3EG 5.32023-10-25
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthenticated attackers.
- CVE-2023-27351HIGHCVSS 7.5EG 9.0⚠ KEV2023-04-20
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRe…
- CVE-2023-27375HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- CVE-2023-27376HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- CVE-2023-27377HIGHCVSS 7.5EG 7.52023-10-25
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
- CVE-2023-27388CRITICALCVSS 9.8EG 9.82023-05-23
Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Cor…
- CVE-2023-27482CRITICALCVSS 10.0EG 10.02023-03-08
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation t…
- CVE-2023-27535MEDIUMCVSS 5.9EG 7.52023-03-30
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool f…
- CVE-2023-27536MEDIUMCVSS 5.9EG 9.82023-03-30
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DEL…
- CVE-2023-27538MEDIUMCVSS 5.5EG 5.52023-03-30
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool …
- CVE-2023-27582CRITICALCVSS 9.1EG 9.12023-03-13
maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. In…
- CVE-2023-2759HIGHCVSS 8.8EG 8.82023-07-17
A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may gain full access to the device by using…
- CVE-2023-27823CRITICALCVSS 9.8EG 9.82023-05-12
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.
- CVE-2023-27877MEDIUMCVSS 5.3EG 5.32023-07-19
IBM Planning Analytics Cartridge for Cloud Pak for Data 4.0 connects to a CouchDB server. An attacker can exploit an insecure password policy to the CouchDB server and collect sensitive information from the database. IBM X-Force ID: 2479…
- CVE-2023-27919MEDIUMCVSS 5.3EG 5.32023-05-10
Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker to alter the information stored in the system.
- CVE-2023-28073HIGHCVSS 8.2EG 8.22023-06-23
Dell BIOS contains an improper authentication vulnerability. A locally authenticated malicious user may potentially exploit this vulnerability by bypassing certain authentication mechanisms in order to elevate privileges on the system.
- CVE-2023-28121CRITICALCVSS 9.8EG 9.82023-04-12
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain …
- CVE-2023-28125MEDIUMCVSS 5.9EG 5.92023-05-09
An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.
- CVE-2023-28182MEDIUMCVSS 6.5EG 6.52023-05-08
The issue was addressed with improved authentication. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A user in a privileged network position m…
- CVE-2023-28325MEDIUMCVSS 6.5EG 6.52023-05-11
An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target roo…
- CVE-2023-28377MEDIUMCVSS 6.7EG 6.72023-11-14
Improper authentication in some Intel(R) NUC Kit NUC11PH USB firmware installation software before version 1.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-28398CRITICALCVSS 9.8EG 9.82023-03-28
Osprey Pump Controller version 1.01 could allow an unauthenticated user to create an account and bypass authentication, thereby gaining unauthorized access to the system. A threat actor could exploit this vulnerability to create a user acc…
- CVE-2023-28461CRITICALCVSS 9.8EG 9.8⚠ KEV2023-03-15
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could t…
- CVE-2023-28473LOWCVSS 3.3EG 3.32023-04-28
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.
- CVE-2023-28503CRITICALCVSS 9.8EG 9.82023-03-29
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can…
- CVE-2023-28540CRITICALCVSS 9.1EG 9.12023-10-03
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
- CVE-2023-28609CRITICALCVSS 9.8EG 9.82023-03-18
api/auth.go in Ansible Semaphore before 2.8.89 mishandles authentication.
- CVE-2023-28646MEDIUMCVSS 4.4EG 4.42023-03-30
Nextcloud android is an android app for interfacing with the nextcloud home server ecosystem. In versions from 3.7.0 and before 3.24.1 an attacker that has access to the unlocked physical device can bypass the Nextcloud Android Pin/passcod…
- CVE-2023-28647MEDIUMCVSS 4.4EG 4.42023-03-30
Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions prior to 4.7.0 when an attacker has physical access to an unlocked device, they may enable the integration into the iOS Files app an…
- CVE-2023-28727CRITICALCVSS 9.6EG 8.82023-03-31
Panasonic AiSEG2 versions 2.00J through 2.93A allows adjacent attackers bypass authentication due to mishandling of X-Forwarded-For headers.
- CVE-2023-28862CRITICALCVSS 9.8EG 9.82023-03-31
An issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling during a password check allow attackers to bypass 2FA verification. Any plugin that tries to deny se…
- CVE-2023-28962MEDIUMCVSS 5.3EG 5.32023-04-17
An Improper Authentication vulnerability in upload-file.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to upload arbitrary files to temporary folders on the device. This issu…
- CVE-2023-28963MEDIUMCVSS 5.3EG 5.32023-04-17
An Improper Authentication vulnerability in cert-mgmt.php, used by the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to read arbitrary files from temporary folders on the device. This issue …
- CVE-2023-28973HIGHCVSS 7.1EG 7.12023-04-17
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks Junos OS Evolved allows a local, authenticated attacker to execute administrative commands that could impact the integrity of the system or system…
- CVE-2023-29032HIGHCVSS 8.1EG 8.12023-05-12
An attacker that has gained access to certain private information can use this to act as other user. Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 3.1.3 before 7.1.0
- CVE-2023-29062LOWCVSS 3.8EG 3.82023-11-28
The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use …
- CVE-2023-29117HIGHCVSS 8.8EG 8.82024-11-05
Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.
- CVE-2023-29129CRITICALCVSS 9.1EG 9.12023-06-13
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 …
- CVE-2023-29155CRITICALCVSS 9.8EG 9.82023-11-20
Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could allow an attacker to obtain admin-level access to the host system.
- CVE-2023-29463HIGHCVSS 8.8EG 8.82023-09-12
The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session data and or log use…
- CVE-2023-2959HIGHCVSS 7.5EG 8.22023-07-17
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2.
- CVE-2023-2975MEDIUMCVSS 5.3EG 5.32023-07-14
Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to aut…
- CVE-2023-29975HIGHCVSS 7.2EG 7.22023-11-09
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
- CVE-2023-30061HIGHCVSS 7.5EG 7.52023-05-01
D-Link DIR-879 v105A1 is vulnerable to Authentication Bypass via phpcgi.
- CVE-2023-30063HIGHCVSS 7.5EG 7.52023-05-01
D-Link DIR-890L FW1.10 A1 is vulnerable to Authentication bypass.
- CVE-2023-30223HIGHCVSS 7.5EG 7.52023-06-16
A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions.
- CVE-2023-3028HIGHCVSS 8.6EG 8.62023-06-01
Insufficient authentication in the MQTT backend (broker) allows an attacker to access and even manipulate the telemetry data of the entire fleet of vehicles using the HopeChart HQT-401 telematics unit. Other models are possibly affected to…
- CVE-2023-30328CRITICALCVSS 9.8EG 9.82023-05-04
An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.
- CVE-2023-30559MEDIUMCVSS 5.2EG 5.22023-07-13
The firmware update package for the wireless card is not properly signed and can be modified.
- CVE-2023-30560MEDIUMCVSS 6.8EG 6.82023-07-13
The configuration from the PCU can be modified without authentication using physical connection to the PCU.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →