CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,940 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 75 of 99
- CVE-2023-52955MEDIUMCVSS 6.5EG 6.52025-01-08
Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- CVE-2023-5326HIGHCVSS 8.8EG 8.82023-10-01
A vulnerability was found in SATO CL4NX-J Plus 1.13.2-u455_r2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component WebConfig. The manipulation leads to improper authentication. The …
- CVE-2023-5328HIGHCVSS 8.8EG 8.82023-10-02
A vulnerability classified as critical has been found in SATO CL4NX-J Plus 1.13.2-u455_r2. This affects an unknown part of the component Cookie Handler. The manipulation with the input auth=user,level1,settings; web=true leads to improper …
- CVE-2023-5329HIGHCVSS 7.5EG 7.52023-10-02
A vulnerability classified as problematic was found in Field Logic DataCube4 up to 20231001. This vulnerability affects unknown code of the file /api/ of the component Web API. The manipulation leads to improper authentication. The exploit…
- CVE-2023-5376CRITICALCVSS 9.1EG 9.12024-01-09
An Improper Authentication vulnerability in Korenix JetNet TFTP allows abuse of this service. This issue affects JetNet devices older than firmware version 2024/01.
- CVE-2023-5502MEDIUMCVSS 5.9EG 5.92026-06-04
On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x a…
- CVE-2023-5627HIGHCVSS 7.5EG 7.52023-11-01
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users…
- CVE-2023-5808HIGHCVSS 6.5EG 8.82023-12-05
SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that …
- CVE-2023-5830CRITICALCVSS 9.8EG 9.82023-10-27
A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper…
- CVE-2023-5844HIGHCVSS 7.2EG 7.22023-10-30
Unverified Password Change in GitHub repository pimcore/admin-ui-classic-bundle prior to 1.2.0.
- CVE-2023-5970HIGHCVSS 8.8EG 8.82023-12-05
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
- CVE-2023-6155MEDIUMCVSS 5.3EG 5.32023-12-26
The Quiz Maker WordPress plugin before 6.4.9.5 does not adequately authorize the `ays_quiz_author_user_search` AJAX action, allowing an unauthenticated attacker to perform a search for users of the system, ultimately leaking user email add…
- CVE-2023-6248CRITICALCVSS 9.8EG 10.02023-11-21
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks…
- CVE-2023-6329CRITICALCVSS 9.8EG 9.82023-11-27
An authentication bypass vulnerability exists in Control iD iDSecure v4.7.32.0. The login routine used by iDS-Core.dll contains a "passwordCustom" option that allows an unauthenticated attacker to compute valid credentials that can be used…
- CVE-2023-6342CRITICALCVSS 9.8EG 9.82023-11-30
Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "p…
- CVE-2023-6343MEDIUMCVSS 5.3EG 5.32023-11-30
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate and access sensitive files using the tiffserver/tssp.aspx 'FN' and 'PN' parameters. This behavior is related to the use of a deprecated ve…
- CVE-2023-6344MEDIUMCVSS 5.3EG 5.32023-11-30
Tyler Technologies Court Case Management Plus allows a remote, unauthenticated attacker to enumerate directories using the tiffserver/te003.aspx or te004.aspx 'ifolder' parameter. This behavior is related to the use of a deprecated version…
- CVE-2023-6353CRITICALCVSS 9.4EG 9.42023-11-30
Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter.
- CVE-2023-6354CRITICALCVSS 9.4EG 9.42023-11-30
Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter.
- CVE-2023-6375HIGHCVSS 7.5EG 7.52023-11-30
Tyler Technologies Court Case Management Plus may store backups in a location that can be accessed by a remote, unauthenticated attacker. Backups may contain sensitive information such as database credentials.
- CVE-2023-6451HIGHCVSS 8.6EG 8.62024-02-16
Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.
- CVE-2023-6483CRITICALCVSS 9.8EG 9.82023-12-18
The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authentication vulnerability in the ADiTaaS backend API. An unauthenticated remote attacker could exploit this vulnerability b…
- CVE-2023-6514HIGHCVSS 8.8EG 8.82023-12-06
The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions. Successful exploitation of…
- CVE-2023-6768CRITICALCVSS 9.8EG 9.82023-12-20
Authentication bypass vulnerability in Amazing Little Poll affecting versions 1.3 and 1.4. This vulnerability could allow an unauthenticated user to access the admin panel without providing any credentials by simply accessing the "lp_admin…
- CVE-2023-6787MEDIUMCVSS 6.5EG 6.52024-04-25
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query p…
- CVE-2023-6847HIGHCVSS 7.5EG 7.52023-12-21
An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using a specially crafted API request. To exploit this vulnerability, an attacker would need network access to the…
- CVE-2023-6907CRITICALCVSS 9.1EG 9.12023-12-18
A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /file-manager/delete.php of the component Deletion Interface. The m…
- CVE-2023-7079MEDIUMCVSS 5.7EG 5.72023-12-29
Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network int…
- CVE-2023-7210CRITICALCVSS 9.8EG 9.82024-01-07
A vulnerability was found in OneNav up to 0.9.33. It has been classified as critical. This affects an unknown part of the file /index.php?c=api of the component API. The manipulation of the argument X-Token leads to improper authentication…
- CVE-2023-7211HIGHCVSS 8.1EG 8.12024-01-07
A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. The manipulation leads to reliance on ip address for authentication. T…
- CVE-2024-0002CRITICALCVSS 10.0EG 10.02024-09-23
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
- CVE-2024-0130HIGHCVSS 8.8EG 8.82024-12-06
NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request through the Ethernet management interface. A successful exploit of th…
- CVE-2024-0568HIGHCVSS 8.8EG 8.82024-02-14
CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.
- CVE-2024-0799CRITICALCVSS 9.8EG 9.82024-03-13
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
- CVE-2024-0822CRITICALCVSS 7.5EG 9.12024-01-25
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.
- CVE-2024-0879MEDIUMCVSS 6.5EG 6.52024-01-25
Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.
- CVE-2024-0988MEDIUMCVSS 6.3EG 6.32024-01-29
A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function checklogin of the file /application/index/common.php. The manipulation of the argument App_User…
- CVE-2024-10020HIGHCVSS 8.1EG 8.12024-11-06
The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to insufficient verification on the user being returned by the social login token. Thi…
- CVE-2024-1006HIGHCVSS 7.3EG 7.32024-01-29
A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of the file application/index/common.php of the component Cookie Handler. The manipulation o…
- CVE-2024-10097HIGHCVSS 8.1EG 8.12024-11-05
The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to insufficient verification on the user being returned by the social login token. …
- CVE-2024-10111HIGHCVSS 8.1EG 8.12024-12-12
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3. This is due to insufficient verification on the user being returned by the social log…
- CVE-2024-10114HIGHCVSS 8.1EG 8.12024-11-05
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This mak…
- CVE-2024-10173HIGHCVSS 7.3EG 7.32024-10-20
A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Console Module. The manipulation with the input /;login leads to improper authenticatio…
- CVE-2024-10327HIGHCVSS 8.1EG 8.12024-10-24
A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selecti…
- CVE-2024-1039CRITICALCVSS 9.8EG 9.82024-02-01
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management of the device.
- CVE-2024-10474CRITICALCVSS 6.5EG 9.12024-10-29
Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.
- CVE-2024-10511MEDIUMCVSS 5.3EG 5.32024-12-11
CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local network repeatedly requests the /accessdenied URL.
- CVE-2024-10620MEDIUMCVSS 5.3EG 5.32024-11-01
A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the component Configuration Center. The manipulation leads to improper authentication.…
- CVE-2024-10963HIGHCVSS 7.4EG 7.42024-11-07
A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the system by pretending to be a trusted hostname, gaining unauthorized access.…
- CVE-2024-11015CRITICALCVSS 9.8EG 9.82024-12-12
The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the 'authenticate_user' user function not implementing sufficient null value checks when settin…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →