CWE-287— Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.— MITRE CWE catalog
4,942 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-287page 88 of 99
- CVE-2025-67791CRITICALCVSS 9.8EG 9.82025-12-17
An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the netwo…
- CVE-2025-67822CRITICALCVSS 9.4EG 9.42026-01-15
A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication m…
- CVE-2025-67859MEDIUMCVSS 5.1EG 5.12026-01-14
A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as well as the daemon’s log settings.This issue affects TLP: from 1.9 before 1.9.1.
- CVE-2025-68402HIGHCVSS 8.2EG 8.22026-03-09
FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 chars to 64. password_verify() is currently being called with a constructed string (SHA-256 nonce + part of a bcrypt has…
- CVE-2025-68640MEDIUMCVSS 5.3EG 5.32026-07-21
The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentica…
- CVE-2025-68663MEDIUMCVSS 5.3EG 5.32026-02-11
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connection…
- CVE-2025-68712MEDIUMCVSS 5.5EG 5.52026-05-27
SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a …
- CVE-2025-68717CRITICALCVSS 9.4EG 9.42026-01-08
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. …
- CVE-2025-68926CRITICALCVSS 9.8EG 9.82025-12-30
RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token `"rustfs rpc"` that is publicly exposed in the source code repository, h…
- CVE-2025-68931HIGHCVSS 7.5EG 7.52026-01-13
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability i…
- CVE-2025-6916HIGHCVSS 8.8EG 8.82025-06-30
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the function Form_Login of the file /formLoginAuth.htm. The manipulation of the argument authCode/goURL leads to missing authen…
- CVE-2025-69197MEDIUMCVSS 6.5EG 6.52026-01-06
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward…
- CVE-2025-6926HIGHCVSS 8.8EG 8.82025-07-03
Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, fro…
- CVE-2025-69273HIGHCVSS 7.5EG 7.52026-01-12
Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spectrum: 24.3.10 and earlier.
- CVE-2025-6979HIGHCVSS 8.8EG 8.82025-10-23
Captive Portal can allow authentication bypass
- CVE-2025-69822HIGHCVSS 7.4EG 7.42026-01-22
An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame
- CVE-2025-70833CRITICALCVSS 9.4EG 9.42026-02-20
An Authentication Bypass vulnerability in Smanga 3.2.7 allows an unauthenticated attacker to reset the password of any user (including the administrator) and fully takeover the account by manipulating POST parameters. The issue stems from …
- CVE-2025-70841CRITICALCVSS 7.5EG 10.02026-02-03
Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encr…
- CVE-2025-7095MEDIUMCVSS 6.1EG 6.12025-07-06
A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component Update Handler. The manipulation leads to improper certificate validation. It is possible …
- CVE-2025-71057HIGHCVSS 8.2EG 8.22026-02-26
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.
- CVE-2025-7114HIGHCVSS 7.5EG 7.52025-07-07
A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as critical. Affected by this vulnerability is the function POST of the file apps/sim/app/api/files/upload/route.ts of the co…
- CVE-2025-7115HIGHCVSS 7.3EG 7.32025-07-07
A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as critical. Affected by this issue is the function PUT of the file apps/rowboat/app/api/uploads/[fileId]/route.ts of the co…
- CVE-2025-71279CRITICALCVSS 9.8EG 9.82026-04-01
XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may be able to compromise the security of Passkey-based authentication.
- CVE-2025-7574CRITICALCVSS 9.8EG 9.82025-07-14
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/restore of the file /cgi-bin/lighttpd.cgi of t…
- CVE-2025-7630MEDIUMCVSS 5.3EG 5.32026-02-18
Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication and Automation Industry and Trade Inc. Wispotter allows Password Brute Forcing, Brute Force. This issue affects Wispot…
- CVE-2025-7699HIGHCVSS 7.1EG 7.12025-07-16
An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to copy arbitrary files from the server file system into their own EZSync folder. The vulnerability is due to a lack of aut…
- CVE-2025-7703MEDIUMCVSS 3.1EG 6.82025-07-16
Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage.
- CVE-2025-7862CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnerability is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component Telnet Service. The manipulation …
- CVE-2025-7875HIGHCVSS 7.5EG 7.52025-07-20
A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This affects an unknown part of the file /debug.jsp. The manipulation leads to improper authentication. It is possible to initiate the atta…
- CVE-2025-7897CRITICALCVSS 9.8EG 9.82025-07-20
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads …
- CVE-2025-7955CRITICALCVSS 9.8EG 9.82025-08-28
The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthentic…
- CVE-2025-8348HIGHCVSS 7.5EG 7.52025-07-31
A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability affects unknown code of the file /home. The manipulation leads to improper authentication. The attack can be initiated …
- CVE-2025-8546MEDIUMCVSS 5.3EG 5.32025-08-05
A vulnerability, which was classified as problematic, was found in atjiu pybbs up to 6.0.0. This affects the function adminlogin/login of the component Verification Code Handler. The manipulation leads to guessable captcha. It is possible …
- CVE-2025-8838CRITICALCVSS 9.8EG 9.82025-08-11
A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8. This vulnerability affects the function preHandle of the file /admin/ of the component Backend Interface. The manipulation of the argumen…
- CVE-2025-8964HIGHCVSS 7.8EG 7.82025-08-14
A vulnerability was identified in code-projects Hostel Management System 1.0. This affects an unknown part of the file hostel_manage.exe of the component Login. The manipulation leads to improper authentication. It is possible to launch th…
- CVE-2025-9063CRITICALCVSS 9.8EG 9.82025-10-14
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the fi…
- CVE-2025-9064CRITICALCVSS 9.1EG 9.12025-10-14
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability …
- CVE-2025-9100MEDIUMCVSS 3.7EG 5.32025-08-18
A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article Comment Handler. The manipulation leads to authentication bypass by c…
- CVE-2025-9265CRITICALCVSS 10.0EG 10.02025-10-13
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user verification, giving them access to state changing actions that should only be initiated by administratorsThis issue affec…
- CVE-2025-9533CRITICALCVSS 9.8EG 9.82025-08-27
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /formLoginAuth.htm. The manipulation of the argument authCode with the input 1 leads to improper authentication. The attack …
- CVE-2025-9803CRITICALCVSS 8.8EG 9.32025-11-25
lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audience) field in the access token issued by Google, which is …
- CVE-2025-9815HIGHCVSS 7.8EG 7.82025-09-02
A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authe…
- CVE-2025-9965CRITICALCVSS 9.3EG 9.32025-09-23
Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any application from/to the device.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build …
- CVE-2025-9994CRITICALCVSS 9.8EG 9.82025-09-09
The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing unauthorized access to anyone with network access.
- CVE-2026-0405HIGHCVSS 7.8EG 7.82026-01-13
An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access the router web interface as an admin.
- CVE-2026-0407HIGHCVSS 8.0EG 8.02026-01-13
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with WiFi authentication or a physical Ethernet port connection to bypass the authentication process and access the admin …
- CVE-2026-0408HIGHCVSS 8.0EG 8.02026-01-13
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the router's IP and review the contents of the dynamically generated webproc file, which records the username and passwo…
- CVE-2026-0558CRITICALCVSS 9.8EG 9.82026-03-29
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce authentication, unlike other fil…
- CVE-2026-0589HIGHCVSS 7.3EG 7.32026-01-05
A vulnerability was found in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the component Administration Backend. The manipulation results in improper authentication. The attack may be performed fro…
- CVE-2026-0629HIGHCVSS 8.7EG 8.72026-01-16
Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models allows an attacker on the LAN to reset the admin password without verification by manipulating client-side state. Attacker…
Map vulnerabilities like CWE-287 to your infrastructure
EchelonGraph correlates every CVE — across CWE-287 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →