CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,942 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 86 of 99
- CVE-2025-52553CRITICALCVSS 9.6EG 9.62025-06-27
authentik is an open-source identity provider. After authorizing access to a RAC endpoint, authentik creates a token which is used for a single connection and is sent to the client in the URL. This token is intended to only be valid for th…
- CVE-2025-52571CRITICALCVSS 9.6EG 9.62025-06-24
Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server…
- CVE-2025-52572CRITICALCVSS 10.0EG 10.02025-06-24
Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have an authenticated session: attacker can use his own Telegram account to gain RCE to the serv…
- CVE-2025-52856CRITICALCVSS 9.8EG 9.82025-08-29
An improper authentication vulnerability has been reported to affect VioStor. If a remote attacker, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following…
- CVE-2025-53013MEDIUMCVSS 5.2EG 5.22025-06-26
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9.10 through 0.9.16 allows a user to authenticate to a Linux host via Himmelblau using an *invalid* Linux Hello PIN, pro…
- CVE-2025-53169HIGHCVSS 7.6EG 7.62025-07-07
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.
- CVE-2025-53545MEDIUMCVSS 6.9EG 6.92025-07-08
Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Users can circumvent 2FA login for users due to a lack of server side validation for the same. This vul…
- CVE-2025-53771CRITICALCVSS 6.5EG 9.02025-07-20
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVE-2025-53778HIGHCVSS 8.8EG 8.82025-08-12
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- CVE-2025-53786HIGHCVSS 8.0EG 8.02025-08-06
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deploy…
- CVE-2025-53793HIGHCVSS 7.5EG 7.52025-08-12
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
- CVE-2025-53845MEDIUMCVSS 6.5EG 6.52025-10-14
An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to obtain information pertaining to the device's health and status, or cause a den…
- CVE-2025-53889MEDIUMCVSS 6.5EG 6.52025-07-15
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with a manual trigger are not validating whether the user triggering the Flow has permi…
- CVE-2025-54154MEDIUMCVSS 6.8EG 6.82025-10-03
An improper authentication vulnerability has been reported to affect QNAP Authenticator. If an attacker gains physical access, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vul…
- CVE-2025-5437MEDIUMCVSS 5.3EG 5.32025-06-02
A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Password Change Handler. The manipulation leads to improper authenti…
- CVE-2025-54376HIGHCVSS 7.5EG 7.52025-09-10
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards the REST admin API. Consequently, an una…
- CVE-2025-54419CRITICALCVSS 10.0EG 10.02025-07-28
A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that are verified when checking signature. T…
- CVE-2025-54452HIGHCVSS 7.3EG 7.32025-07-23
Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.
- CVE-2025-54573MEDIUMCVSS 4.3EG 4.32025-07-30
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.1.0 through 2.41.0, email verification was not enforced when using Basic HTTP Authentication. As a result, users could create accounts us…
- CVE-2025-54761HIGHCVSS 8.0EG 8.02025-09-19
An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.
- CVE-2025-54786MEDIUMCVSS 5.3EG 5.32025-08-07
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.6 and 8.8.0, the broken authentication in the legacy iCal service allows unauthenticated access to meeting data. An …
- CVE-2025-54888HIGHCVSS 8.7EG 8.72025-08-09
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1.5.0-dev.636 through 1.5.4, 1.6.0-dev.754 through 1.6.7, 1.7.0-pr.251.885 through 1.7.8 and …
- CVE-2025-54918HIGHCVSS 8.8EG 8.82025-09-09
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- CVE-2025-5495CRITICALCVSS 9.8EG 9.82025-06-03
A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknown part of the component URL Handler. The manipulation with the input %00currentsetting.htm leads to improper authentica…
- CVE-2025-5512CRITICALCVSS 9.8EG 9.82025-06-03
A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file /api/sys/user/verifyPassword/ of the component Administrator Backend. The manipulation leads to …
- CVE-2025-55169MEDIUMCVSS 6.5EG 6.52025-08-12
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.ph…
- CVE-2025-55171HIGHCVSS 7.5EG 7.52025-08-12
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, the application does not check authentication at endpoint /html/personalizacao_remover.php allowing anonymous …
- CVE-2025-55234HIGHCVSS 8.8EG 8.82025-09-09
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB…
- CVE-2025-55241CRITICALCVSS 10.0EG 10.02025-09-04
Azure Entra ID Elevation of Privilege Vulnerability
- CVE-2025-55293CRITICALCVSS 9.4EG 9.42025-08-18
Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with a new key. First sending a empty key bypasses 'if (p.public_key.size > 0) {', cleari…
- CVE-2025-55340HIGHCVSS 7.0EG 7.02025-10-14
Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally.
- CVE-2025-5597CRITICALCVSS 10.0EG 10.02025-06-04
Improper Authentication vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Authentication Bypass.This issue affects airleader MASTER: 3.00571.
- CVE-2025-56333CRITICALCVSS 9.8EG 9.82025-12-29
An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component
- CVE-2025-56447CRITICALCVSS 9.8EG 9.82025-10-22
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
- CVE-2025-56578MEDIUMCVSS 5.7EG 5.72025-09-10
An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authentication mechanisms
- CVE-2025-56752CRITICALCVSS 9.4EG 9.42025-09-03
A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, providing them with unrestricted access to alter administrative settings and potentially seize c…
- CVE-2025-56764MEDIUMCVSS 5.3EG 6.52025-09-29
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), allowing an attacker to enumerate valid usernames.
- CVE-2025-57278HIGHCVSS 8.8EG 8.82025-09-09
The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address, the router grants access to any other cli…
- CVE-2025-57434HIGHCVSS 8.8EG 8.82025-09-22
Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username is creabox and the password begins with the string creacast, regardless of what…
- CVE-2025-58060HIGHCVSS 8.0EG 8.02025-09-11
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` …
- CVE-2025-58065MEDIUMCVSS 6.5EG 6.52025-09-11
Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other non-database authentication methods, the password reset endpoint remains registered and acce…
- CVE-2025-58443CRITICALCVSS 9.1EG 9.12025-09-06
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where t…
- CVE-2025-5870HIGHCVSS 7.3EG 7.32025-06-09
A vulnerability has been found in TRENDnet TV-IP121W 1.1.1 Build 36 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/setup.cgi of the component Web Interface. The manipulation leads …
- CVE-2025-5871MEDIUMCVSS 5.3EG 5.32025-06-09
A vulnerability was found in Papendorf SOL Connect Center 3.3.0.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to missing authentication. The att…
- CVE-2025-5872MEDIUMCVSS 5.3EG 5.32025-06-09
A vulnerability was found in eGauge EG3000 Energy Monitor 3.6.3. It has been classified as problematic. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authentication. It is possible to init…
- CVE-2025-5876MEDIUMCVSS 5.3EG 5.32025-06-09
A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack …
- CVE-2025-5906CRITICALCVSS 9.8EG 9.82025-06-10
A vulnerability classified as critical has been found in code-projects Laundry System 1.0. This affects an unknown part of the file /data/. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. T…
- CVE-2025-59280LOWCVSS 3.1EG 3.12025-10-14
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
- CVE-2025-59704MEDIUMCVSS 4.6EG 4.62025-12-02
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow an attacker to gain access the the BIOS menu because is has no password.
- CVE-2025-5985HIGHCVSS 7.3EG 7.32025-06-10
A vulnerability was found in code-projects School Fees Payment System 1.0 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper authentication. The attack may be launched remot…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →