CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,941 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 79 of 99
- CVE-2024-38825MEDIUMCVSS 6.4EG 6.42025-06-13
The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not need acce…
- CVE-2024-39340HIGHCVSS 8.8EG 8.82024-07-12
The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web interface and the user portal. Affected versions include UTM 11.…
- CVE-2024-39723MEDIUMCVSS 4.6EG 4.62024-07-08
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data. IBM X-Force ID: 295935.
- CVE-2024-39767MEDIUMCVSS 4.2EG 4.22024-07-15
Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID…
- CVE-2024-39830HIGHCVSS 8.1EG 8.12024-07-03
Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster tokens which allows an attacker to retrieve the remote cluster…
- CVE-2024-4024HIGHCVSS 7.3EG 7.32024-04-25
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker wi…
- CVE-2024-40648MEDIUMCVSS 5.4EG 5.42024-07-18
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's ow…
- CVE-2024-40653HIGHCVSS 7.3EG 7.32025-09-02
In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the background due to a logic error in the code. This could lead to local escalation of privilege with no additional executio…
- CVE-2024-40713HIGHCVSS 7.8EG 7.82024-09-07
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
- CVE-2024-40778LOWCVSS 3.3EG 3.32024-07-29
An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Photos in the Hidden Photos Album may be viewed without authentication.
- CVE-2024-40794MEDIUMCVSS 5.3EG 5.32024-07-29
This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing tabs may be accessed without authentication.
- CVE-2024-41195CRITICALCVSS 9.8EG 9.82025-05-22
An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- CVE-2024-41196CRITICALCVSS 9.8EG 9.82025-05-22
An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- CVE-2024-41197CRITICALCVSS 9.8EG 9.82025-05-22
An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- CVE-2024-41198CRITICALCVSS 9.8EG 9.82025-05-22
An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- CVE-2024-41199HIGHCVSS 7.2EG 7.22025-05-22
An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- CVE-2024-4129HIGHCVSS 8.8EG 8.82024-05-14
Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager…
- CVE-2024-41589HIGHCVSS 8.8EG 8.82024-10-03
DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.
- CVE-2024-41798CRITICALCVSS 9.8EG 9.82024-10-08
A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative access via Modbus TCP interface. Attackers with access to the Modbus TCP interface could …
- CVE-2024-41800MEDIUMCVSS 4.8EG 4.82024-07-25
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that th…
- CVE-2024-41829LOWCVSS 3.5EG 3.52024-07-22
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
- CVE-2024-41929HIGHCVSS 8.8EG 8.82024-09-18
Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
- CVE-2024-42038HIGHCVSS 8.8EG 8.82024-08-08
Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- CVE-2024-42164MEDIUMCVSS 4.3EG 4.32024-08-12
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.
- CVE-2024-42172MEDIUMCVSS 5.3EG 5.32025-01-11
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logi…
- CVE-2024-42336HIGHCVSS 8.2EG 8.22024-08-20
Servision - CWE-287: Improper Authentication
- CVE-2024-42462CRITICALCVSS 9.8EG 9.82024-08-16
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.
- CVE-2024-4303HIGHCVSS 8.8EG 8.82024-04-29
ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentials can bypass MFA, allowing them to successfully log into the APP.
- CVE-2024-43240CRITICALCVSS 9.4EG 9.42024-08-19
Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7.
- CVE-2024-43409MEDIUMCVSS 6.5EG 6.52024-08-20
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in …
- CVE-2024-43685CRITICALCVSS 9.8EG 9.82024-10-04
Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
- CVE-2024-44127MEDIUMCVSS 5.3EG 5.32024-09-17
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.
- CVE-2024-44202MEDIUMCVSS 5.3EG 5.32024-09-17
An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.
- CVE-2024-44821MEDIUMCVSS 5.3EG 5.32024-09-04
ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a result, an attacker can exploit this fla…
- CVE-2024-44843MEDIUMCVSS 5.9EG 5.92025-04-15
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.
- CVE-2024-45036MEDIUMCVSS 4.3EG 4.32024-08-26
Tophat is a mobile applications testing harness. An Improper Access Control vulnerability can expose the `TOPHAT_APP_TOKEN` token stored in `~/.tophatrc` through use of a malicious Tophat URL controlled by the attacker. The vulnerability a…
- CVE-2024-45042MEDIUMCVSS 4.4EG 4.42024-09-26
Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a number of preconditions, the `highest_available` setting will incorrectly assume that the identity’s highest availab…
- CVE-2024-45051HIGHCVSS 8.2EG 8.22024-10-07
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been …
- CVE-2024-45106HIGHCVSS 8.1EG 8.12024-12-03
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only possible if: * ozone.s3g.secret.http.enab…
- CVE-2024-45113HIGHCVSS 7.5EG 7.52024-09-13
ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access and affect the int…
- CVE-2024-45115CRITICALCVSS 9.8EG 9.82024-10-10
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthoriz…
- CVE-2024-45148HIGHCVSS 8.8EG 8.82024-10-10
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerabilit…
- CVE-2024-45216CRITICALCVSS 9.8EG 9.82024-10-16
Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any…
- CVE-2024-45346HIGHCVSS 8.8EG 8.82024-08-28
The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the same time, we also welcome more outstanding and professional security experts and secu…
- CVE-2024-45347CRITICALCVSS 9.6EG 9.62025-06-23
An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation logic is flawed and can be exploited by attackers to Unauthorized access to the victim’s device.
- CVE-2024-45369HIGHCVSS 8.1EG 8.12024-11-22
The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.
- CVE-2024-45404HIGHCVSS 8.1EG 8.12024-12-12
OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an attacker with valid credentials or a malicious user who commits internal fraud can bre…
- CVE-2024-45750HIGHCVSS 7.3EG 7.32024-09-25
An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and…
- CVE-2024-45823HIGHCVSS 8.1EG 8.12024-09-12
CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able…
- CVE-2024-4601MEDIUMCVSS 6.7EG 6.72024-05-07
An incorrect authentication vulnerability has been found in Socomec Net Vision affecting version 7.20. This vulnerability allows an attacker to perform a brute force attack on the application and recover a valid session, because the applic…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →