CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,940 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 74 of 99
- CVE-2023-46942HIGHCVSS 7.5EG 7.52024-01-13
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
- CVE-2023-46963MEDIUMCVSS 5.3EG 5.32023-11-04
An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function.
- CVE-2023-47127MEDIUMCVSS 5.4EG 5.42023-11-14
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In typo3 installations there are always at least two different sites. Eg. first.example.org and second.example.com. In affected versions a session …
- CVE-2023-47189MEDIUMCVSS 5.3EG 5.32024-06-04
Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.2.0.
- CVE-2023-47222CRITICALCVSS 9.6EG 9.62024-04-26
An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vul…
- CVE-2023-47256MEDIUMCVSS 5.5EG 5.52024-02-01
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
- CVE-2023-47304HIGHCVSS 7.8EG 7.82023-12-05
An issue was discovered in Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device.
- CVE-2023-47504HIGHCVSS 6.5EG 7.52024-04-24
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.
- CVE-2023-48121MEDIUMCVSS 5.3EG 5.32023-11-28
An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xx…
- CVE-2023-4816HIGHCVSS 8.8EG 8.82023-09-11
A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. This vulnerability can be exploited by an authenticated user per-forming an Equipment Tag Out holde…
- CVE-2023-48228CRITICALCVSS 9.8EG 9.82023-11-21
authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_v…
- CVE-2023-48257HIGHCVSS 7.8EG 7.82024-01-10
The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users…
- CVE-2023-48312CRITICALCVSS 9.8EG 9.82023-11-24
capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the user is authenticated based on the `TokenReview` result. All …
- CVE-2023-48703HIGHCVSS 7.5EG 7.52024-03-06
RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to how the `xmlsec1` command line tool is called internally to verify the signature of SAML a…
- CVE-2023-48747MEDIUMCVSS 6.5EG 6.52024-06-04
Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster for WooCommerce: from n/a through 7.1.2.
- CVE-2023-48865MEDIUMCVSS 6.5EG 6.52024-04-11
An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.
- CVE-2023-49105CRITICALCVSS 9.8EG 9.82023-11-21
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs bec…
- CVE-2023-49262CRITICALCVSS 9.8EG 9.82024-01-12
The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.
- CVE-2023-49340CRITICALCVSS 9.8EG 9.82024-03-09
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.
- CVE-2023-4939MEDIUMCVSS 5.3EG 5.32023-10-21
The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authentication token for the /wp-json/salesmanago/v1/callbackApiV3 API endpoint which is simply a…
- CVE-2023-49646MEDIUMCVSS 6.5EG 6.52023-12-13
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
- CVE-2023-49790MEDIUMCVSS 4.3EG 4.32023-12-22
The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform. Prior to version 4.9.2, the application can be used without providing the 4 digit PIN code. Nextcloud iOS Files app should be …
- CVE-2023-49791MEDIUMCVSS 5.4EG 5.42023-12-22
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9…
- CVE-2023-4985HIGHCVSS 7.8EG 7.82023-09-15
A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown function of the file Project.xml. The manipulation leads to improper authentication. An attack has to be approached locall…
- CVE-2023-50127MEDIUMCVSS 5.9EG 5.92024-01-11
Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an attacker to bring the alarm system to a disarmed state from a…
- CVE-2023-50275HIGHCVSS 7.5EG 7.52024-01-23
HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.
- CVE-2023-50430MEDIUMCVSS 6.4EG 6.42023-12-09
The Goodix Fingerprint Device, as shipped in Dell Inspiron 15 computers, does not follow the Secure Device Connection Protocol (SDCP) when enrolling via Linux, and accepts an unauthenticated configuration packet to select the Windows templ…
- CVE-2023-50714HIGHCVSS 8.8EG 8.82023-12-22
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways. First, the `authCod…
- CVE-2023-50804LOWCVSS 3.7EG 3.72024-06-05
An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300…
- CVE-2023-50919CRITICALCVSS 9.8EG 9.82024-01-12
An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT13…
- CVE-2023-50934MEDIUMCVSS 5.3EG 5.32024-02-02
IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor authentication scheme. IBM X-Force ID: 275114.
- CVE-2023-51405HIGHCVSS 8.2EG 8.22024-04-24
Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BookingPress: from n/a through 1.0.74.
- CVE-2023-51442HIGHCVSS 8.6EG 8.62023-12-21
Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endpoint, allowing for authentication bypass. This exploit enables unauthorized access to any …
- CVE-2023-51471HIGHCVSS 8.2EG 8.22024-04-24
Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7.
- CVE-2023-51472CRITICALCVSS 9.8EG 9.82024-04-24
Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7.
- CVE-2023-51477CRITICALCVSS 9.8EG 9.82024-04-24
Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyBoss Theme: from n/a through 2.4.60.
- CVE-2023-51478CRITICALCVSS 9.8EG 9.82024-04-25
Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.
- CVE-2023-51482CRITICALCVSS 9.9EG 9.92024-04-25
Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Eazy Plugin Manager: from n/a through 4.1.2.
- CVE-2023-51484CRITICALCVSS 9.8EG 9.82024-04-25
Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from n/a through 3.8.
- CVE-2023-51511MEDIUMCVSS 6.5EG 6.52024-06-04
Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.3.
- CVE-2023-51708HIGHCVSS 8.6EG 8.62023-12-22
Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System ma…
- CVE-2023-51717CRITICALCVSS 9.8EG 9.82024-01-09
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
- CVE-2023-51761HIGHCVSS 8.3EG 8.32024-02-09
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.
- CVE-2023-51982CRITICALCVSS 9.8EG 9.82024-01-30
CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP r…
- CVE-2023-52111HIGHCVSS 7.5EG 7.52024-01-16
Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.
- CVE-2023-52160MEDIUMCVSS 6.5EG 6.52024-02-22
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_d…
- CVE-2023-52161HIGHCVSS 7.5EG 7.52024-02-22
The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skippin…
- CVE-2023-52210MEDIUMCVSS 5.3EG 5.32025-12-23
Vulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.0.
- CVE-2023-5246HIGHCVSS 8.8EG 8.82023-10-23
Authentication Bypass by Capture-replay in SICK Flexi Soft Gateways with Partnumbers 1044073, 1127717, 1130282, 1044074, 1121597, 1099832, 1051432, 1127487, 1069070, 1112296, 1044072, 1121596, 1099830 allows an unauthenticated remote attac…
- CVE-2023-52540HIGHCVSS 7.5EG 7.52024-04-08
Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →