CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,940 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 76 of 99
- CVE-2024-11087HIGHCVSS 8.1EG 8.12025-03-08
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on …
- CVE-2024-11186CRITICALCVSS 10.0EG 10.02025-05-08
On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products…
- CVE-2024-11209MEDIUMCVSS 6.3EG 6.32024-11-14
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate th…
- CVE-2024-11293HIGHCVSS 8.1EG 8.12024-12-04
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress is vulnerable to authentication bypass in all versions up…
- CVE-2024-11322HIGHCVSS 7.5EG 7.52025-01-15
A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. …
- CVE-2024-1147CRITICALCVSS 9.8EG 9.82024-03-21
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.
- CVE-2024-1148CRITICALCVSS 9.8EG 9.82024-03-21
Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.
- CVE-2024-11494HIGHCVSS 7.5EG 7.52024-11-20
**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could allow an unauthenticated attacker to read some device information via a crafted HTTP HEAD …
- CVE-2024-11671MEDIUMCVSS 5.4EG 5.42024-11-25
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.
- CVE-2024-11680CRITICALCVSS 9.8EG 9.8⚠ KEV2024-11-26
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of th…
- CVE-2024-11917HIGHCVSS 8.1EG 8.12025-04-25
The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', …
- CVE-2024-12264CRITICALCVSS 9.8EG 9.82025-01-07
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost REST API endpoi…
- CVE-2024-12287CRITICALCVSS 9.8EG 9.82024-12-18
The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes i…
- CVE-2024-12310HIGHCVSS 7.0EG 7.02025-07-23
A vulnerability in Imprivata Enterprise Access Management (formerly Imprivata OneSign) allows bypassing the login screen of the shared kiosk workstation and allows unauthorized access to the underlying Windows system through the already l…
- CVE-2024-12510MEDIUMCVSS 6.7EG 6.72025-02-03
If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.
- CVE-2024-12869MEDIUMCVSS 4.3EG 4.32025-03-20
In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email a…
- CVE-2024-12919CRITICALCVSS 9.8EG 9.82025-01-14
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.13.7. This is due to the pms_pb_paym…
- CVE-2024-13088HIGHCVSS 7.8EG 7.82025-06-06
An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerabili…
- CVE-2024-13111MEDIUMCVSS 5.6EG 5.62025-01-02
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/u…
- CVE-2024-13309MEDIUMCVSS 5.4EG 5.42025-01-09
Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.
- CVE-2024-1347MEDIUMCVSS 4.3EG 4.32024-04-25
An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted em…
- CVE-2024-13528HIGHCVSS 7.5EG 7.52025-02-12
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.9.5. This is due to the presence of a shortcode that will generate a confirmation link with…
- CVE-2024-13804CRITICALCVSS 9.8EG 9.82025-03-30
Unauthenticated RCE in HPE Insight Cluster Management Utility
- CVE-2024-14034CRITICALCVSS 9.8EG 9.82026-04-02
Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP…
- CVE-2024-1609HIGHCVSS 8.7EG 8.72024-12-25
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
- CVE-2024-1610CRITICALCVSS 9.8EG 9.82024-12-18
In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
- CVE-2024-1735CRITICALCVSS 9.1EG 9.12024-02-26
A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. All users who rely on armeria-saml older than version 1.27.2 must upgrade to 1.27.2 or lat…
- CVE-2024-1817HIGHCVSS 7.3EG 7.32024-02-23
A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the function dmlogin of the file indexDM_load.php of the component Cookie Handler. …
- CVE-2024-20301MEDIUMCVSS 6.2EG 6.22024-03-06
A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected Windows device. This vulnerability is due to a failure to i…
- CVE-2024-20738CRITICALCVSS 9.8EG 9.82024-02-15
Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication …
- CVE-2024-20803MEDIUMCVSS 6.5EG 6.82024-01-04
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
- CVE-2024-20815HIGHCVSS 8.0EG 8.02024-02-06
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
- CVE-2024-20816HIGHCVSS 8.0EG 8.02024-02-06
Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
- CVE-2024-20856MEDIUMCVSS 4.3EG 4.32024-05-07
Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.
- CVE-2024-20889MEDIUMCVSS 5.9EG 5.92024-07-02
Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.
- CVE-2024-20890MEDIUMCVSS 5.3EG 5.32024-07-02
Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.
- CVE-2024-20900MEDIUMCVSS 4.0EG 4.02024-07-02
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
- CVE-2024-2112MEDIUMCVSS 5.9EG 5.92024-04-09
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it …
- CVE-2024-21390HIGHCVSS 7.1EG 7.12024-03-12
Microsoft Authenticator Elevation of Privilege Vulnerability
- CVE-2024-21410CRITICALCVSS 9.8EG 9.8⚠ KEV2024-02-13
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2024-21427HIGHCVSS 7.5EG 7.52024-03-12
Windows Kerberos Security Feature Bypass Vulnerability
- CVE-2024-21543HIGHCVSS 7.1EG 7.12024-12-13
Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid creden…
- CVE-2024-21632CRITICALCVSS 9.8EG 9.82024-01-02
omniauth-microsoft_graph provides an Omniauth strategy for the Microsoft Graph API. Prior to versions 2.0.0, the implementation did not validate the legitimacy of the `email` attribute of the user nor did it give/document an option to do s…
- CVE-2024-21635HIGHCVSS 7.5EG 7.52025-11-14
Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of expiring. If a user finds th…
- CVE-2024-21638CRITICALCVSS 9.1EG 9.12024-01-10
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azu…
- CVE-2024-21654MEDIUMCVSS 4.8EG 4.82024-01-12
Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email account takeover. However, a workaround on the forgotten password form all…
- CVE-2024-21899CRITICALCVSS 9.8EG 9.82024-03-08
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed t…
- CVE-2024-22206CRITICALCVSS 9.0EG 9.02024-01-12
Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3.
- CVE-2024-22245CRITICALCVSS 9.6EG 9.62024-02-20
Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser …
- CVE-2024-22247MEDIUMCVSS 4.8EG 4.82024-04-02
VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the …
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →