CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,941 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 78 of 99
- CVE-2024-28992HIGHCVSS 7.6EG 7.62024-07-17
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.
- CVE-2024-29757HIGHCVSS 7.3EG 7.32024-04-05
there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2024-29837HIGHCVSS 8.8EG 8.82024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.
- CVE-2024-29849CRITICALCVSS 9.8EG 9.82024-05-22
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
- CVE-2024-30299CRITICALCVSS 10.0EG 10.02024-06-13
Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized ac…
- CVE-2024-3080CRITICALCVSS 9.8EG 9.82024-06-14
Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.
- CVE-2024-30939MEDIUMCVSS 6.8EG 6.82024-04-25
An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an account via a flaw in the factory reset procedure.
- CVE-2024-31800MEDIUMCVSS 6.8EG 6.82024-08-15
Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.
- CVE-2024-3263CRITICALCVSS 9.8EG 9.82024-05-14
YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and en…
- CVE-2024-33110CRITICALCVSS 9.1EG 9.12024-05-06
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.
- CVE-2024-34093MEDIUMCVSS 5.3EG 5.32024-05-06
An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attacker could potentially bypass intended whitelisting when X-Forwarded-For header is enabled.
- CVE-2024-34103HIGHCVSS 8.1EG 8.12024-06-13
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized a…
- CVE-2024-34340CRITICALCVSS 9.1EG 9.12024-05-14
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. …
- CVE-2024-34399CRITICALCVSS 9.8EG 9.82024-09-18
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are …
- CVE-2024-34596HIGHCVSS 5.9EG 7.52024-07-02
Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.
- CVE-2024-34788MEDIUMCVSS 6.5EG 6.52024-08-07
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information
- CVE-2024-3487LOWCVSS 3.5EG 3.52024-05-15
Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.
- CVE-2024-35184MEDIUMCVSS 5.5EG 5.52024-05-15
Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is exp…
- CVE-2024-35248HIGHCVSS 7.3EG 7.32024-06-11
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
- CVE-2024-35670MEDIUMCVSS 5.3EG 5.32024-06-04
Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.
- CVE-2024-35775MEDIUMCVSS 5.9EG 5.92024-08-12
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Authentication vulnerability in Soliloquy Team Slider by Soliloquy allows Cross-Site Scripting (XSS).This issue affects Slider by Soliloq…
- CVE-2024-36130CRITICALCVSS 9.8EG 9.82024-08-07
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
- CVE-2024-36132HIGHCVSS 7.5EG 8.22024-08-07
Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.
- CVE-2024-36264CRITICALCVSS 9.8EG 9.82024-06-12
** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submari…
- CVE-2024-36266CRITICALCVSS 9.3EG 9.32024-06-11
A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication requests. This could allow a local attacker to bypass authentication, thereby gaining admi…
- CVE-2024-36402MEDIUMCVSS 5.3EG 5.32025-01-16
Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote …
- CVE-2024-36444HIGHCVSS 8.1EG 8.12024-08-22
cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.
- CVE-2024-3701CRITICALCVSS 9.8EG 9.82024-04-15
The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.
- CVE-2024-37019CRITICALCVSS 9.8EG 9.82024-06-03
Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.
- CVE-2024-37028MEDIUMCVSS 5.3EG 5.32024-08-14
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- CVE-2024-37085CRITICALCVSS 6.8EG 9.0⚠ KEV2024-06-25
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://bl…
- CVE-2024-37152MEDIUMCVSS 5.3EG 5.32024-06-06
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidde…
- CVE-2024-37233MEDIUMCVSS 4.3EG 4.32024-06-24
Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Play.Ht: from n/a through 3.6.4.
- CVE-2024-37313HIGHCVSS 7.3EG 7.32024-06-14
Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded …
- CVE-2024-37367HIGHCVSS 7.5EG 7.52024-06-14
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This act…
- CVE-2024-37368HIGHCVSS 7.5EG 7.52024-06-14
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the l…
- CVE-2024-37408HIGHCVSS 7.3EG 7.32024-06-08
fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for Sudo. NOTE: the supplier disputes this because they believe issue resolution would involve…
- CVE-2024-37893MEDIUMCVSS 5.9EG 5.92024-06-17
Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious users to bypass the MFA-check. This allows malicious users to use password spraying to gai…
- CVE-2024-37897MEDIUMCVSS 5.4EG 5.42024-06-20
SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and WebClient support password reset. This feature is disabled in the default configuration. In…
- CVE-2024-38099MEDIUMCVSS 5.9EG 5.92024-07-09
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
- CVE-2024-38124CRITICALCVSS 9.0EG 9.02024-10-08
Windows Netlogon Elevation of Privilege Vulnerability
- CVE-2024-38139HIGHCVSS 8.7EG 8.72024-10-15
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
- CVE-2024-38225HIGHCVSS 8.8EG 8.82024-09-10
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
- CVE-2024-3826HIGHCVSS 8.6EG 8.62024-07-02
In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.
- CVE-2024-38351MEDIUMCVSS 5.4EG 5.42024-06-18
Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In order to be exploited users must have both OAuth2 and Password auth methods enabled. A possible…
- CVE-2024-38426MEDIUMCVSS 5.4EG 5.42025-03-03
While processing the authentication message in UE, improper authentication may lead to information disclosure.
- CVE-2024-38433MEDIUMCVSS 6.7EG 6.72024-07-11
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by …
- CVE-2024-38523HIGHCVSS 7.5EG 7.52024-06-27
Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authentication flow has multiple issues that weakens its one-time nature. Specifically, the lack of 2FA for changing security s…
- CVE-2024-38810MEDIUMCVSS 6.5EG 6.52024-08-20
Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.
- CVE-2024-38822LOWCVSS 2.7EG 2.72025-06-13
Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another minion.
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →