CWE-287— Improper Authentication
4,329 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 66 of 87
- CVE-2023-33563HIGHCVSS 8.8EG 8.82023-08-01
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
- CVE-2023-3362MEDIUMCVSS 5.3EG 5.32023-07-13
An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error information if a project was imported from GitHub.
- CVE-2023-34124CRITICALCVSS 9.8EG 9.82023-07-13
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
- CVE-2023-34137CRITICALCVSS 9.8EG 9.82023-07-13
SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass vulnerability. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-…
- CVE-2023-34196HIGHCVSS 8.2EG 8.22023-08-03
In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations using OAuth, disclosure of CA certificates (attributes and p…
- CVE-2023-34246MEDIUMCVSS 4.2EG 4.22023-06-12
Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. Prior to version 5.6.6, Doorkeeper automatically processes authorization requests without user consent for public clients that have been previous approved. Public clients are inh…
- CVE-2023-34340CRITICALCVSS 9.8EG 9.82023-06-21
Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 contains a defect in the user authentication process that may succeed when invalid credentials …
- CVE-2023-34367MEDIUMCVSS 6.5EG 6.52023-06-14
Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devic…
- CVE-2023-34388MEDIUMCVSS 6.5EG 6.52023-11-30
An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication. See product Instructio…
- CVE-2023-3470MEDIUMCVSS 6.0EG 6.02023-08-02
Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or …
- CVE-2023-34998HIGHCVSS 8.1EG 8.12023-09-05
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff …
- CVE-2023-35078CRITICALCVSS 9.8EG 10.0⚠ KEV2023-07-25
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
- CVE-2023-35082CRITICALCVSS 9.8EG 10.0⚠ KEV2023-08-15
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-350…
- CVE-2023-35137HIGHCVSS 7.5EG 7.52023-11-30
An improper authentication vulnerability in the authentication module of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to obtain system information b…
- CVE-2023-35154HIGHCVSS 7.2EG 7.22023-06-23
Knowage is an open source analytics and business intelligence suite. Starting in version 6.0.0 and prior to version 8.1.8, an attacker can register and activate their account without having to click on the link included in the email, allow…
- CVE-2023-35785HIGHCVSS 8.1EG 9.82023-08-28
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 …
- CVE-2023-35794HIGHCVSS 8.8EG 8.82023-10-27
An issue was discovered in Cassia Access Controller 2.1.1.2303271039. The Web SSH terminal endpoint (spawned console) can be accessed without authentication. Specifically, there is no session cookie validation on the Access Controller; ins…
- CVE-2023-35874MEDIUMCVSS 6.0EG 6.02023-07-11
SAP NetWeaver Application Server ABAP and ABAP Platform - version KRNL64NUC, 7.22, KRNL64NUC 7.22EXT, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KERNEL 7.22, KERNEL, 7.53, KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.89, KERNEL 7.5…
- CVE-2023-35901LOWCVSS 2.7EG 2.72023-07-17
IBM Robotic Process Automation 21.0.0 through 21.0.7.6 and 23.0.0 through 23.0.6 is vulnerable to client side validation bypass which could allow invalid changes or values in some fields. IBM X-Force ID: 259380.
- CVE-2023-3591MEDIUMCVSS 4.8EG 4.82023-07-17
Mattermost fails to invalidate previously generated password reset tokens when a new reset token was created.
- CVE-2023-35940HIGHCVSS 7.5EG 7.52023-07-05
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.8, an incorrect rights check on a file allows an unauthenticated user to be able to access dashboards data. Version 10.0.8 contain…
- CVE-2023-3597MEDIUMCVSS 5.0EG 5.02024-04-25
A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication fac…
- CVE-2023-36004HIGHCVSS 7.5EG 7.52023-12-12
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
- CVE-2023-3622MEDIUMCVSS 4.3EG 4.62023-07-26
Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource
- CVE-2023-3638CRITICALCVSS 9.8EG 9.82023-07-19
In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application.
- CVE-2023-36466LOWCVSS 3.5EG 3.52023-07-14
Discourse is an open source discussion platform. When editing a topic, there is a vulnerability that enables a user to bypass the topic title validations for things like title length, number of emojis in title and blank topic titles. The i…
- CVE-2023-36648HIGHCVSS 8.2EG 8.22023-12-12
Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and writing data in Ap…
- CVE-2023-36655CRITICALCVSS 9.8EG 9.82023-12-06
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowerc…
- CVE-2023-36724MEDIUMCVSS 5.5EG 5.52023-10-10
Windows Power Management Service Information Disclosure Vulnerability
- CVE-2023-36815HIGHCVSS 7.3EG 7.32023-07-03
Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.]…
- CVE-2023-36926LOWCVSS 3.7EG 3.72023-08-08
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the attacker to gather som…
- CVE-2023-37226CRITICALCVSS 9.8EG 9.82024-09-10
Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.
- CVE-2023-37266CRITICALCVSS 9.8EG 9.82023-07-17
CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addre…
- CVE-2023-37268MEDIUMCVSS 6.4EG 6.42023-07-14
Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a user with SSO enabled an attacker may authenticate as an other user. Any user account which does not have a second facto…
- CVE-2023-37283HIGHCVSS 8.1EG 8.12023-10-25
Under a very specific and highly unrecommended configuration, authentication bypass is possible in the PingFederate Identifier First Adapter
- CVE-2023-37284HIGHCVSS 8.8EG 8.82023-09-06
Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command via a crafted request to bypass authentication.
- CVE-2023-37362HIGHCVSS 7.2EG 7.22023-07-19
Weintek Weincloud v0.13.6 could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.
- CVE-2023-37471CRITICALCVSS 9.1EG 9.12023-07-20
Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of …
- CVE-2023-37544HIGHCVSS 7.5EG 7.52023-12-20
Improper Authentication vulnerability in Apache Pulsar WebSocket Proxy allows an attacker to connect to the /pingpong endpoint without authentication. This issue affects Apache Pulsar WebSocket Proxy: from 2.8.0 through 2.8.*, from 2.9.0 …
- CVE-2023-37918MEDIUMCVSS 6.8EG 6.82023-07-21
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. A vulnerability has been found in Dapr that allows bypassing API token authentication, which is used by the Dapr sidecar to authenticate…
- CVE-2023-38096CRITICALCVSS 9.8EG 9.82024-05-03
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of NETGEAR ProSAFE Network Management System.…
- CVE-2023-38367MEDIUMCVSS 6.5EG 6.52024-02-29
IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2) allows CRUD Operations with a…
- CVE-2023-38372MEDIUMCVSS 5.9EG 5.92024-02-29
An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platform user. IBM X-Force ID: 261201.
- CVE-2023-38534HIGHCVSS 8.6EG 8.62024-03-13
Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC.
- CVE-2023-38555HIGHCVSS 8.8EG 8.82023-07-26
Authentication bypass vulnerability in Fujitsu network devices Si-R series and SR-M series allows a network-adjacent unauthenticated attacker to obtain, change, and/or reset configuration settings of the affected products. Affected product…
- CVE-2023-38585HIGHCVSS 8.8EG 8.82023-08-23
Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information pr…
- CVE-2023-38691MEDIUMCVSS 5.0EG 5.02023-08-04
matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix server can use a foreign user's MXID in an OpenID exchange, allowing a bad actor to impers…
- CVE-2023-38735MEDIUMCVSS 5.7EG 5.72023-10-22
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. I…
- CVE-2023-39069CRITICALCVSS 9.8EG 9.82023-09-11
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.
- CVE-2023-39112MEDIUMCVSS 6.5EG 6.52023-08-04
ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →