CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,940 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 77 of 99
- CVE-2024-22394CRITICALCVSS 9.8EG 9.82024-02-08
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware version SonicOS 7.1…
- CVE-2024-22395MEDIUMCVSS 6.3EG 6.32024-02-24
Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.
- CVE-2024-2244MEDIUMCVSS 5.3EG 5.32024-03-27
REST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successful service invocation. The anomaly doesn’t exist with other credential combinations.
- CVE-2024-22441CRITICALCVSS 9.8EG 9.82024-06-13
HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.
- CVE-2024-22442CRITICALCVSS 9.8EG 9.82024-07-16
The vulnerability could be remotely exploited to bypass authentication.
- CVE-2024-23219MEDIUMCVSS 6.2EG 6.22024-01-23
The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly disabled.
- CVE-2024-23251MEDIUMCVSS 4.6EG 4.62024-06-10
An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. An attacker with physical access may be able to leak Mail…
- CVE-2024-23255CRITICALCVSS 2.4EG 9.12024-03-08
An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden Photos Album may be viewed without authentication.
- CVE-2024-23465HIGHCVSS 8.3EG 8.32024-07-17
The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthenticated user to gain domain admin access within the Active Directory environment.
- CVE-2024-23470CRITICALCVSS 9.6EG 9.62024-07-17
The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and executables.
- CVE-2024-23471CRITICALCVSS 9.6EG 9.62024-07-17
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.
- CVE-2024-23629CRITICALCVSS 9.6EG 9.62024-01-26
An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information.
- CVE-2024-23637MEDIUMCVSS 4.2EG 4.22024-01-31
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repea…
- CVE-2024-23647MEDIUMCVSS 6.5EG 6.52024-01-30
Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE offers. PKCE adds the code_challenge parameter to the authorization request and adds…
- CVE-2024-23767HIGHCVSS 8.8EG 8.82024-06-26
An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.
- CVE-2024-23792MEDIUMCVSS 5.3EG 5.32024-01-29
When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to know the UUID. While the legitimate user completes the comment, the malic…
- CVE-2024-23806MEDIUMCVSS 5.3EG 5.32024-02-07
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
- CVE-2024-23813HIGHCVSS 7.3EG 7.32024-02-13
A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector of the affected product lacks proper authentication. An unauthenticated attacker could access the endpoints, and potenti…
- CVE-2024-24279HIGHCVSS 8.8EG 8.82024-04-08
An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower functions.
- CVE-2024-24496CRITICALCVSS 9.8EG 9.82024-02-08
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.
- CVE-2024-2450HIGHCVSS 8.8EG 8.82024-03-15
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take…
- CVE-2024-24554HIGHCVSS 8.2EG 8.22024-06-24
Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This allows attackers to authenticate against the Bludit API.
- CVE-2024-24592CRITICALCVSS 9.8EG 9.82024-02-06
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files.
- CVE-2024-24698MEDIUMCVSS 4.9EG 4.92024-02-14
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
- CVE-2024-24771HIGHCVSS 7.7EG 7.72024-02-07
Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their credentials (username + password) compromise…
- CVE-2024-24830CRITICALCVSS 9.9EG 9.92024-02-08
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any a…
- CVE-2024-25106CRITICALCVSS 9.1EG 9.12024-02-08
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulner…
- CVE-2024-25128CRITICALCVSS 9.1EG 9.12024-02-29
Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested Op…
- CVE-2024-25157MEDIUMCVSS 6.5EG 6.52024-08-14
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized informat…
- CVE-2024-25313HIGHCVSS 8.8EG 8.82024-02-09
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.
- CVE-2024-25618MEDIUMCVSS 4.2EG 4.22024-02-14
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to existing local users with the same e-mail address. This resu…
- CVE-2024-25652CRITICALCVSS 7.6EG 9.82024-03-14
In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN MODE (with access to the Report functionality) to gain unauthorized access…
- CVE-2024-25699HIGHCVSS 8.5EG 8.52024-04-04
There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows and Linux, and ArcGIS Enterprise versions 11.1 and below on Kubernetes, which under uni…
- CVE-2024-26331HIGHCVSS 7.5EG 8.02024-04-30
ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing cli…
- CVE-2024-27137MEDIUMCVSS 5.3EG 5.32025-02-04
In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration files to manipulate the RMI registry to perform a man-in-the-middle attack and capture user names and passwords used…
- CVE-2024-27275HIGHCVSS 7.4EG 7.42024-06-15
IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege can configure a physical file trigger to execute with the privil…
- CVE-2024-27767CRITICALCVSS 10.0EG 10.02024-03-18
CWE-287: Improper Authentication may allow Authentication Bypass
- CVE-2024-27835LOWCVSS 2.4EG 2.42024-05-14
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to access notes from the lock screen.
- CVE-2024-27867MEDIUMCVSS 4.3EG 4.32024-06-26
An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request t…
- CVE-2024-27923HIGHCVSS 8.8EG 8.82024-03-21
Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient permission validation and inadequate file name validation. This may lead to remote code ex…
- CVE-2024-28006MEDIUMCVSS 5.3EG 5.32024-03-28
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2,…
- CVE-2024-28007CRITICALCVSS 9.8EG 9.82024-03-28
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2,…
- CVE-2024-28009CRITICALCVSS 9.8EG 9.82024-03-28
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2,…
- CVE-2024-28012CRITICALCVSS 9.8EG 9.82024-03-28
Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2,…
- CVE-2024-28188MEDIUMCVSS 5.3EG 5.32024-05-23
Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a speci…
- CVE-2024-28200CRITICALCVSS 9.1EG 9.12024-07-01
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code …
- CVE-2024-28255CRITICALCVSS 9.8EG 9.82024-03-15
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and ve…
- CVE-2024-2862CRITICALCVSS 9.1EG 9.12024-03-25
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
- CVE-2024-2873CRITICALCVSS 9.1EG 9.12024-03-25
A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.
- CVE-2024-28735HIGHCVSS 8.1EG 8.12024-03-20
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →