CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,941 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 81 of 99
- CVE-2024-57045CRITICALCVSS 9.8EG 9.82025-02-18
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg…
- CVE-2024-57046HIGHCVSS 8.8EG 8.82025-02-18
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the …
- CVE-2024-5732HIGHCVSS 7.3EG 7.32024-06-07
A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects unknown code of the component Proxy Port. The manipulation leads to improper authentication. The attack can be initiat…
- CVE-2024-57432CRITICALCVSS 7.5EG 9.12025-01-31
macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management, making it i…
- CVE-2024-57490HIGHCVSS 7.7EG 7.72025-03-21
Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system account including the system administrator through a logical flaw.
- CVE-2024-57491HIGHCVSS 8.8EG 8.82025-08-20
Authentication Bypass vulnerability in jobx up to v1.0.1-RELEASE allows an attacker can exploit this vulnerability to access sensitive API without any token via the preHandle function.
- CVE-2024-5798LOWCVSS 2.6EG 2.62024-06-12
Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This may have resulted in Vault validating a JWT the audience and role-bound claims do not match,…
- CVE-2024-5805CRITICALCVSS 9.1EG 9.12024-06-25
Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0.0.
- CVE-2024-5806CRITICALCVSS 9.1EG 9.12024-06-25
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.…
- CVE-2024-58363MEDIUMCVSS 6.3EG 6.32026-07-18
SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database if …
- CVE-2024-5956MEDIUMCVSS 6.5EG 6.52024-09-05
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly
- CVE-2024-5957MEDIUMCVSS 6.3EG 6.32024-09-05
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
- CVE-2024-6057CRITICALCVSS 9.8EG 9.82024-06-17
Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mo…
- CVE-2024-6078HIGHCVSS 8.6EG 8.62024-08-14
CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user…
- CVE-2024-6107CRITICALCVSS 9.6EG 9.62025-07-21
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.
- CVE-2024-6174HIGHCVSS 8.8EG 8.82025-06-26
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
- CVE-2024-6235HIGHCVSS 8.8EG 8.82024-07-10
Sensitive information disclosure in NetScaler Console
- CVE-2024-6248HIGHCVSS 7.5EG 7.52024-11-22
Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authenticatio…
- CVE-2024-6397CRITICALCVSS 9.8EG 9.82024-07-11
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 0.1.0.44. This is due to insufficient verification of the API key. This makes it possi…
- CVE-2024-6535MEDIUMCVSS 5.3EG 5.32024-07-17
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with a static cookie-secret. In certain circumstances, this may allow an atta…
- CVE-2024-6576HIGHCVSS 7.3EG 7.32024-07-29
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0…
- CVE-2024-7012CRITICALCVSS 9.8EG 9.82024-09-04
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of …
- CVE-2024-7050HIGHCVSS 8.3EG 8.32024-07-26
Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular scenarios.This issue affects OpenText Directory Services: 24.2.
- CVE-2024-7346HIGHCVSS 7.2EG 7.22024-09-03
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. This has been corrected so that default certificates are no longer c…
- CVE-2024-7395CRITICALCVSS 9.3EG 9.32024-08-05
An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2.
- CVE-2024-7401HIGHCVSS 7.5EG 7.52024-08-26
Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this is a static token, if leaked, cannot be rotated or revoked. A mali…
- CVE-2024-7487MEDIUMCVSS 5.8EG 5.82025-05-22
An improper authentication vulnerability exists in WSO2 Identity Server 7.0.0 due to an implementation flaw that allows app-native authentication to be bypassed when an invalid object is passed. Exploitation of this vulnerability could en…
- CVE-2024-7593CRITICALCVSS 9.8EG 9.8⚠ KEV2024-08-13
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
- CVE-2024-7745MEDIUMCVSS 6.5EG 6.52024-08-28
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
- CVE-2024-7746CRITICALCVSS 9.8EG 9.82024-08-13
Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwi…
- CVE-2024-7763CRITICALCVSS 9.8EG 9.82024-10-24
In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.
- CVE-2024-7870MEDIUMCVSS 6.5EG 6.52024-09-04
The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Exposure in all versions up to, and including, 9.7.1 and 10.4.2, respectively, through publi…
- CVE-2024-7923CRITICALCVSS 9.8EG 9.82024-09-04
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly unsetting headers b…
- CVE-2024-8053HIGHCVSS 8.2EG 8.22025-03-20
In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST re…
- CVE-2024-8181CRITICALCVSS 9.8EG 9.82024-08-27
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
- CVE-2024-8642HIGHCVSS 8.1EG 8.12024-09-11
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass…
- CVE-2024-8956CRITICALCVSS 9.1EG 9.1⚠ KEV2024-09-17
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent without an HTTP Authorization header.…
- CVE-2024-9133MEDIUMCVSS 6.6EG 6.62025-01-10
A user with administrator privileges is able to retrieve authentication tokens
- CVE-2024-9683MEDIUMCVSS 4.8EG 4.82024-10-17
A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reducing the overall security of password enforcement. While th…
- CVE-2024-9927HIGHCVSS 7.2EG 7.22024-10-23
The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all versions up to and including 2.0.5. This is due to the improper implementation of allow_payment_without_login function. Thi…
- CVE-2024-9946HIGHCVSS 8.1EG 8.12024-11-06
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user …
- CVE-2024-9947HIGHCVSS 8.1EG 8.12024-10-23
The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it pos…
- CVE-2025-0070CRITICALCVSS 9.9EG 9.92025-01-14
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploit…
- CVE-2025-0217HIGHCVSS 7.8EG 7.82025-05-05
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools…
- CVE-2025-0249LOWCVSS 3.3EG 3.32025-07-25
HCL IEM is affected by an improper invalidation of access or JWT token vulnerability. A token was not invalidated which may allow attackers to access sensitive data without authorization.
- CVE-2025-0604MEDIUMCVSS 5.4EG 5.42025-01-22
A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expi…
- CVE-2025-0605MEDIUMCVSS 4.6EG 4.62025-05-22
An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.
- CVE-2025-0637CRITICALCVSS 9.8EG 9.82025-01-23
It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to access private areas and/or areas …
- CVE-2025-0663MEDIUMCVSS 6.8EG 6.82025-09-23
A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a …
- CVE-2025-0672LOWCVSS 3.3EG 3.32025-09-23
An authentication bypass vulnerability exists in multiple WSO2 products when FIDO authentication is enabled. When a user account is deleted, the system does not automatically remove associated FIDO registration data. If a new user account …
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →