CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,942 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 85 of 99
- CVE-2025-4015MEDIUMCVSS 5.3EG 5.32025-04-28
A vulnerability was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It has been rated as critical. Affected by this issue is the function list of the file novel-system/src/main/java/com/java2nb/system/controlle…
- CVE-2025-4018MEDIUMCVSS 5.3EG 5.32025-04-28
A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file novel-crawl/src/main/java/com/java2nb/novel…
- CVE-2025-4019HIGHCVSS 7.3EG 7.32025-04-28
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function genCode of the file novel-admin/src/main/java/com/java2nb/common/controller/Genera…
- CVE-2025-41023MEDIUMCVSS 6.9EG 6.92026-02-19
An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to bypass authentication mechanisms. Once inside the web application, the attacker can use any of its features regardless of…
- CVE-2025-41064CRITICALCVSS 9.3EG 9.32025-10-02
Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as an authentication method.
- CVE-2025-41108CRITICALCVSS 9.8EG 9.82025-10-22
The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external attack station, impersonating the control station (tablet) and gaining unauthorised full cont…
- CVE-2025-41110HIGHCVSS 8.8EG 8.82025-10-22
Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the robot's WiFi and view all its data, as it runs on ROS 2 without default authentication. In a…
- CVE-2025-4144CRITICALCVSS 9.8EG 9.82025-05-01
PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped. Fixed in: …
- CVE-2025-41459HIGHCVSS 7.8EG 7.82025-07-21
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN atte…
- CVE-2025-4268MEDIUMCVSS 5.3EG 5.32025-05-05
A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument topicurl with the input RebootSystem leads …
- CVE-2025-43281HIGHCVSS 7.8EG 8.42025-10-15
The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.
- CVE-2025-43995CRITICALCVSS 9.8EG 9.82025-10-24
Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechani…
- CVE-2025-44005CRITICALCVSS 10.0EG 10.02025-12-17
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.
- CVE-2025-44083CRITICALCVSS 9.8EG 9.82025-05-21
An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication
- CVE-2025-4494HIGHCVSS 7.3EG 7.32025-05-09
A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin of the file NoNeedLoginController.java of the component Admin Backend. The manipulation leads to improper authenticati…
- CVE-2025-45583CRITICALCVSS 9.1EG 9.12025-09-12
Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.
- CVE-2025-45777CRITICALCVSS 9.8EG 9.82025-07-25
An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request.
- CVE-2025-46348CRITICALCVSS 10.0EG 10.02025-04-29
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could …
- CVE-2025-46548MEDIUMCVSS 6.5EG 6.52025-06-03
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted use…
- CVE-2025-46572CRITICALCVSS 9.3EG 9.32025-05-06
passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication b…
- CVE-2025-46573HIGHCVSS 8.6EG 8.62025-05-06
passport-wsfed-saml2 provides passport strategy for both WS-fed and SAML2 protocol. A vulnerability present starting in version 3.0.5 up to and including version 4.6.3 allows an attacker to impersonate any user during SAML authentication b…
- CVE-2025-46590MEDIUMCVSS 6.3EG 6.32025-05-06
Bypass vulnerability in the network search instruction authentication module Impact: Successful exploitation of this vulnerability can bypass authentication and enable access to some network search functions.
- CVE-2025-46607MEDIUMCVSS 6.6EG 6.62026-04-17
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit t…
- CVE-2025-46630MEDIUMCVSS 6.5EG 6.52025-05-01
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.
- CVE-2025-46631MEDIUMCVSS 6.5EG 6.52025-05-01
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.
- CVE-2025-46641MEDIUMCVSS 6.6EG 6.62026-04-17
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with remote access could potentially exploit t…
- CVE-2025-47275CRITICALCVSS 9.1EG 9.12025-05-15
Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session cookies of applications using the Auth0-PHP SDK configured with CookieStore have authenticati…
- CVE-2025-4755HIGHCVSS 7.3EG 7.32025-05-16
A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been classified as critical. This affects the function sub_497DE4 of the file /H5/netconfig.asp. The manipulation leads to improper authentication. It is possible t…
- CVE-2025-47790MEDIUMCVSS 6.4EG 6.42025-05-16
Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have a bug with session …
- CVE-2025-47889CRITICALCVSS 9.8EG 9.82025-05-14
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any usernam…
- CVE-2025-48370LOWCVSS 2.7EG 2.72025-05-27
auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserById, deleteUser, updateUserById, listFactors and deleteFactor did not require the user supplied values to be valid UUIDs.…
- CVE-2025-48746MEDIUMCVSS 6.5EG 6.52025-05-28
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.
- CVE-2025-48909HIGHCVSS 7.1EG 7.12025-06-06
Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-49001CRITICALCVSS 9.8EG 9.82025-06-03
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fi…
- CVE-2025-49012MEDIUMCVSS 5.4EG 5.42025-06-05
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau versions 0.9.0 through 0.9.14 and 1.00-alpha are vulnerable to a privilege escalation issue when Entra ID group-based access restrictions are confi…
- CVE-2025-49146HIGHCVSS 8.2EG 8.22025-06-11
pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to …
- CVE-2025-49591CRITICALCVSS 9.1EG 9.12025-06-18
CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that compromises a user's creden…
- CVE-2025-49706CRITICALCVSS 6.5EG 9.0⚠ KEV2025-07-08
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-4978CRITICALCVSS 9.8EG 9.82025-05-20
A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /BRS_top.html of the component Basic Authentication. The manipulation leads to improper aut…
- CVE-2025-49812HIGHCVSS 7.4EG 7.42025-07-10
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine option…
- CVE-2025-49831CRITICALCVSS 9.8EG 9.82025-07-15
An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. Cyber…
- CVE-2025-49851CRITICALCVSS 9.8EG 9.82025-06-24
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product.
- CVE-2025-50901CRITICALCVSS 9.8EG 9.82025-08-20
JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file reading.
- CVE-2025-51451CRITICALCVSS 9.8EG 9.82025-08-13
In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
- CVE-2025-5149HIGHCVSS 8.1EG 8.12025-05-25
A vulnerability was found in WCMS up to 8.3.11. It has been declared as critical. Affected by this vulnerability is the function getMemberByUid of the file /index.php?articleadmin/getallcon of the component Login. The manipulation of the a…
- CVE-2025-52054MEDIUMCVSS 5.3EG 5.32025-08-28
An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. T…
- CVE-2025-52294MEDIUMCVSS 5.7EG 5.72025-07-01
Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen and view the wallet balance.
- CVE-2025-52376CRITICALCVSS 9.8EG 9.82025-07-15
An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassin…
- CVE-2025-52395CRITICALCVSS 9.8EG 9.82025-08-21
An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint that fails to validate the identity of the requester properly
- CVE-2025-5247HIGHCVSS 7.3EG 7.32025-05-27
A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function LoadUrl of the file \view\url.go. The manipulation of the argument r leads to improper authentication. The attack may b…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →