CWE-287— Improper Authentication
4,340 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 79 of 87
- CVE-2025-31271HIGHCVSS 7.5EG 7.52025-09-15
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be accepted on a locked macOS device, even with notifications disabled on the lock screen.
- CVE-2025-31478HIGHCVSS 8.2EG 8.22025-04-16
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restric…
- CVE-2025-3222CRITICALCVSS 9.3EG 0.02025-11-07
Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows.
- CVE-2025-3268MEDIUMCVSS 5.3EG 5.32025-04-04
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentica…
- CVE-2025-32815MEDIUMCVSS 6.5EG 6.52025-05-22
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
- CVE-2025-32875MEDIUMCVSS 5.7EG 9.82025-06-20
An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any …
- CVE-2025-32877CRITICALCVSS 9.8EG 9.82025-06-20
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works pairing method. This method does not implement any authenti…
- CVE-2025-32879HIGHCVSS 8.8EG 8.82025-06-20
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attacker to connect with the device via BLE if no other device is connected. While connected, n…
- CVE-2025-32975CRITICALCVSS 10.0EG 10.0⚠ KEV2025-06-24
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability tha…
- CVE-2025-34026HIGHCVSS 7.5EG 9.0⚠ KEV2025-05-21
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged…
- CVE-2025-34186CRITICALCVSS 9.8EG 9.82025-09-16
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate c…
- CVE-2025-3621CRITICALCVSS 9.6EG 9.62025-07-15
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injec…
- CVE-2025-3627MEDIUMCVSS 4.3EG 4.32025-04-25
A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).
- CVE-2025-3634MEDIUMCVSS 4.3EG 4.32025-04-25
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finish…
- CVE-2025-3659CRITICALCVSS 9.4EG 0.02025-05-12
Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP I…
- CVE-2025-37093CRITICALCVSS 9.8EG 9.82025-06-02
An authentication bypass vulnerability exists in HPE StoreOnce Software.
- CVE-2025-37106HIGHCVSS 7.3EG 7.32025-07-16
An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
- CVE-2025-37107HIGHCVSS 7.3EG 7.32025-07-16
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
- CVE-2025-37184CRITICALCVSS 9.8EG 6.52026-01-14
A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account witho…
- CVE-2025-37731MEDIUMCVSS 6.8EG 6.82025-12-15
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate…
- CVE-2025-3850LOWCVSS 3.7EG 3.72025-04-22
A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The manipulation leads to improper authentication. The attack m…
- CVE-2025-3910MEDIUMCVSS 5.4EG 5.42025-04-29
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
- CVE-2025-3935HIGHCVSS 8.1EG 9.0⚠ KEV2025-04-25
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It …
- CVE-2025-4015MEDIUMCVSS 5.3EG 5.32025-04-28
A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of the file novel-system/src/main/java/com/java2nb/system/controlle…
- CVE-2025-4018MEDIUMCVSS 5.3EG 5.32025-04-28
A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file novel-crawl/src/main/java/com/java2nb/novel…
- CVE-2025-4019HIGHCVSS 7.3EG 7.32025-04-28
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function genCode of the file novel-admin/src/main/java/com/java2nb/common/controller/Genera…
- CVE-2025-41023NONECVSS 0.0EG 0.02026-02-19
An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of…
- CVE-2025-41064CRITICALCVSS 9.3EG 0.02025-10-02
Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as an authentication method.
- CVE-2025-41108CRITICALCVSS 9.8EG 9.82025-10-22
The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station, impersonating the control station (tablet) and gaining unauthorised full cont…
- CVE-2025-41110HIGHCVSS 8.8EG 8.82025-10-22
Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the robot's WiFi and view all its data, as it runs on ROS 2 without default authentication. In a…
- CVE-2025-4144CRITICALCVSS 9.8EG 9.82025-05-01
PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: …
- CVE-2025-41459HIGHCVSS 7.8EG 7.82025-07-21
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN atte…
- CVE-2025-4268MEDIUMCVSS 5.3EG 5.32025-05-05
A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input RebootSystem leads …
- CVE-2025-43281HIGHCVSS 7.8EG 8.42025-10-15
The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.
- CVE-2025-43995CRITICALCVSS 9.8EG 9.82025-10-24
Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechani…
- CVE-2025-44005CRITICALCVSS 10.0EG 10.02025-12-17
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.
- CVE-2025-44083CRITICALCVSS 9.8EG 9.82025-05-21
An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication
- CVE-2025-4494HIGHCVSS 7.3EG 7.32025-05-09
A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authenticati…
- CVE-2025-45583CRITICALCVSS 9.1EG 9.12025-09-12
Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.
- CVE-2025-45777CRITICALCVSS 9.8EG 9.82025-07-25
An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request.
- CVE-2025-46348CRITICALCVSS 10.0EG 10.02025-04-29
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could …
- CVE-2025-46548MEDIUMCVSS 6.5EG 6.52025-06-03
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted use…
- CVE-2025-46572CRITICALCVSS 9.3EG 0.02025-05-06
passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication b…
- CVE-2025-46573HIGHCVSS 8.6EG 0.02025-05-06
passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication b…
- CVE-2025-46590MEDIUMCVSS 6.3EG 6.32025-05-06
Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search functions.
- CVE-2025-46607MEDIUMCVSS 6.6EG 6.62026-04-17
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit t…
- CVE-2025-46630MEDIUMCVSS 6.5EG 6.52025-05-01
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.
- CVE-2025-46631MEDIUMCVSS 6.5EG 6.52025-05-01
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.
- CVE-2025-46641MEDIUMCVSS 6.6EG 6.62026-04-17
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit t…
- CVE-2025-47275CRITICALCVSS 9.1EG 9.12025-05-15
Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session cookies of applications using the Auth0-PHP SDK configured with CookieStore have authenticati…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →