CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,942 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 84 of 99
- CVE-2025-2747CRITICALCVSS 9.8EG 9.8⚠ KEV2025-03-24
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administ…
- CVE-2025-27641CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-2024-009.
- CVE-2025-27672CRITICALCVSS 9.8EG 9.82025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows OAUTH Security Bypass OVE-20230524-0016.
- CVE-2025-2771MEDIUMCVSS 5.3EG 5.32025-04-23
BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit thi…
- CVE-2025-2859CRITICALCVSS 9.8EG 9.82025-03-28
An attacker with network access, could capture traffic and obtain user cookies, allowing the attacker to steal the active user session and make changes to the device via web, depending on the privileges obtained by the user.
- CVE-2025-29627MEDIUMCVSS 6.8EG 6.82025-06-09
An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module
- CVE-2025-29773MEDIUMCVSS 5.8EG 5.82025-03-13
Froxlor is open-source server administration software. A vulnerability in versions prior to 2.2.6 allows users (such as resellers or customers) to create accounts with the same email address as an existing account. This creates potential i…
- CVE-2025-29813CRITICALCVSS 10.0EG 10.02025-05-08
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-29906HIGHCVSS 8.6EG 8.62025-04-29
Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user with…
- CVE-2025-30114CRITICALCVSS 9.1EG 9.12025-03-18
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pairing mechanism relies solely on the connecting device's MAC address. By obtaining the MAC address through network scan…
- CVE-2025-30116HIGHCVSS 7.5EG 7.52025-03-18
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Remotely Dumping of Video Footage and the Live Video Stream can occur. It allows remote attackers to access and download recorded video footage from the SD card via…
- CVE-2025-30168MEDIUMCVSS 6.9EG 6.92025-03-21
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd party authentication handling of Parse Server allows the authentication credentials of some specific …
- CVE-2025-30214HIGHCVSS 7.5EG 7.52025-03-25
Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover. Versions 14.89.0 and 15.51.0 fix the issue. …
- CVE-2025-30215CRITICALCVSS 9.6EG 9.62025-04-16
NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.27 and 2.11.1, the management of JetStream assets happens with messages in the $JS. subject…
- CVE-2025-30282CRITICALCVSS 9.1EG 9.12025-04-08
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage t…
- CVE-2025-30287HIGHCVSS 8.2EG 8.22025-04-08
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A low privileged attacker with local access…
- CVE-2025-30361CRITICALCVSS 9.8EG 9.82025-03-27
WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to change a user's password without verifying the old password. This issue exists in the control.p…
- CVE-2025-30430CRITICALCVSS 9.8EG 9.82025-03-31
This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. Password autofill may fill in passwords after failing authentication.
- CVE-2025-30432MEDIUMCVSS 6.4EG 6.42025-03-31
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to at…
- CVE-2025-3061MEDIUMCVSS 6.6EG 6.62025-03-31
Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.
- CVE-2025-3062MEDIUMCVSS 6.6EG 6.62025-03-31
Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.
- CVE-2025-30733MEDIUMCVSS 6.5EG 6.52025-04-15
Vulnerability in the RDBMS Listener component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows unauthenticated attacker with network access …
- CVE-2025-31122CRITICALCVSS 9.0EG 9.02025-03-31
scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to login to any account by changing the username in the username field.
- CVE-2025-31228MEDIUMCVSS 6.8EG 6.82025-05-12
The issue was addressed with improved authentication. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacker with physical access to a device may be able to access notes from the lock screen.
- CVE-2025-31264MEDIUMCVSS 4.6EG 4.62025-05-29
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access to a locked device may be able to view sensitive u…
- CVE-2025-31267MEDIUMCVSS 4.6EG 4.62025-07-10
An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.
- CVE-2025-31271HIGHCVSS 7.5EG 7.52025-09-15
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime calls can appear or be accepted on a locked macOS device, even with notifications disabled on the lock screen.
- CVE-2025-31478HIGHCVSS 8.2EG 8.22025-04-16
Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely by being able to authenticate with a single-sign on authentication backend, meaning the organization places no restric…
- CVE-2025-3222CRITICALCVSS 9.3EG 9.32025-11-07
Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows.
- CVE-2025-3268MEDIUMCVSS 5.3EG 5.32025-04-04
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentica…
- CVE-2025-32815MEDIUMCVSS 6.5EG 6.92025-05-22
An issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
- CVE-2025-32875CRITICALCVSS 5.7EG 9.82025-06-20
An issue was discovered in the COROS application through 3.8.12 for Android. Bluetooth pairing and bonding is neither initiated nor enforced by the application itself. Also, the watch does not enforce pairing and bonding. As a result, any …
- CVE-2025-32877CRITICALCVSS 9.8EG 9.82025-06-20
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works pairing method. This method does not implement any authenti…
- CVE-2025-32879HIGHCVSS 8.8EG 8.82025-06-20
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This allows an attacker to connect with the device via BLE if no other device is connected. While connected, n…
- CVE-2025-32975CRITICALCVSS 10.0EG 10.0⚠ KEV2025-06-24
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability tha…
- CVE-2025-34026CRITICALCVSS 7.5EG 9.0⚠ KEV2025-05-21
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged…
- CVE-2025-34027CRITICALCVSS 10.0EG 10.02025-05-21
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for …
- CVE-2025-34186CRITICALCVSS 9.8EG 9.82025-09-16
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate c…
- CVE-2025-3621CRITICALCVSS 9.6EG 9.62025-07-15
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injec…
- CVE-2025-3627MEDIUMCVSS 4.3EG 4.32025-04-25
A security vulnerability was discovered in Moodle that allows some users to access sensitive information about other students before they finish verifying their identities using two-factor authentication (2FA).
- CVE-2025-3634MEDIUMCVSS 4.3EG 4.32025-04-25
A security vulnerability was discovered in Moodle that allows students to enroll themselves in courses without completing all the necessary safety checks. Specifically, users can sign up for courses prematurely, even if they haven't finish…
- CVE-2025-3659CRITICALCVSS 9.4EG 9.42025-05-12
Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServer TS - prior to and including 82000747_AA, build date 06/17/2022 * Digi One SP/Digi One SP I…
- CVE-2025-37093CRITICALCVSS 9.8EG 9.82025-06-02
An authentication bypass vulnerability exists in HPE StoreOnce Software.
- CVE-2025-37106HIGHCVSS 7.3EG 7.32025-07-16
An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
- CVE-2025-37107HIGHCVSS 7.3EG 7.32025-07-16
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
- CVE-2025-37184CRITICALCVSS 9.8EG 9.82026-01-14
A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account witho…
- CVE-2025-37731MEDIUMCVSS 6.8EG 6.82025-12-15
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate…
- CVE-2025-3850LOWCVSS 3.7EG 3.72025-04-22
A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The manipulation leads to improper authentication. The attack m…
- CVE-2025-3910MEDIUMCVSS 5.4EG 5.42025-04-29
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
- CVE-2025-3935CRITICALCVSS 8.1EG 9.0⚠ KEV2025-04-25
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It …
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →