CWE-287: Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

783
Total CVEs
347
Critical
320
High
8.4
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
67
2025
217
2024
134
2023
115
2022
70

Top Affected Vendors

1 Apache 15
2 Huawei 12
3 Qualcomm 12
4 Microsoft 11
5 Debian 10
6 Dlink 10
7 Cisco 10
8 Dell 9
9 Google 8
10 Fedoraproject 8

All Improper Authentication CVEs (783)

CVE-2026-1740
7.3

This vulnerability allows remote attackers to bypass authentication on EFM ipTIME A8004T routers via improper authentication in the Hidden Hiddenlogin...

Feb 2, 2026
CVE-2026-1202
7.3

This vulnerability allows remote attackers to bypass authentication in CRMEB systems by manipulating the openId parameter in the appleLogin function. ...

Jan 20, 2026
CVE-2025-15458
7.3

This vulnerability allows attackers to bypass authentication in MiniCMS versions up to 1.8 by exploiting an unknown function in the article handler co...

Jan 5, 2026
CVE-2025-15457
7.3

This vulnerability allows remote attackers to bypass authentication in MiniCMS's trash file restore functionality, potentially enabling unauthorized a...

Jan 5, 2026
CVE-2025-15456
7.3

This vulnerability in MiniCMS allows attackers to bypass authentication mechanisms and potentially publish unauthorized pages. It affects MiniCMS vers...

Jan 5, 2026
CVE-2025-15099
7.3

This vulnerability allows remote attackers to bypass authentication in simstudioai sim by manipulating the INTERNAL_API_SECRET argument in the CRON Se...

Dec 26, 2025
CVE-2025-15097
7.3

This vulnerability in Alteryx Server allows attackers to bypass authentication via manipulation of the /gallery/api/status/ endpoint. Remote attackers...

Dec 26, 2025
CVE-2025-11942
7.3

This vulnerability allows attackers to bypass the pairing authentication mechanism in 70mai X200 dashcams, enabling unauthorized access to the device....

Oct 19, 2025
CVE-2025-11661
7.3

CVE-2025-11661 is an authentication bypass vulnerability in ProjectsAndPrograms School Management System that allows attackers to access functionality...

Oct 13, 2025
CVE-2025-11287
7.3

CVE-2025-11287 is an authentication bypass vulnerability in samanhappy MCPHub's SSE service that allows remote attackers to access protected functiona...

Oct 5, 2025
CVE-2025-8838
7.3

This CVE describes an authentication bypass vulnerability in WinterChenS my-site's backend interface. Attackers can manipulate URI parameters to acces...

Aug 11, 2025
CVE-2025-8348
7.3

This critical vulnerability in Kehua Charging Pile Cloud Platform 1.0 allows attackers to bypass authentication mechanisms via the /home endpoint. Rem...

Jul 31, 2025
CVE-2025-7897
7.3

CVE-2025-7897 is an authentication bypass vulnerability in harry0703 MoneyPrinterTurbo's API endpoint that allows attackers to bypass token verificati...

Jul 20, 2025
CVE-2025-7875
7.3

This critical vulnerability in Metasoft MetaCRM allows attackers to bypass authentication via the /debug.jsp endpoint, potentially gaining unauthorize...

Jul 20, 2025
CVE-2025-7862
7.3

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to enable Telnet service without authentication by manipulating the telnet_...

Jul 20, 2025
CVE-2025-37106
7.3

This CVE describes an authentication bypass and information disclosure vulnerability in HPE AutoPass License Server (APLS) versions before 9.18. Attac...

Jul 16, 2025
CVE-2025-7114
7.3

This critical vulnerability in SimStudioAI allows unauthenticated remote attackers to bypass authentication and upload files via the session handler A...

Jul 7, 2025
CVE-2025-5985
7.3

CVE-2025-5985 is an improper authentication vulnerability in code-projects School Fees Payment System 1.0 that allows attackers to bypass authenticati...

Jun 10, 2025
CVE-2025-5906
7.3

CVE-2025-5906 is a critical authentication bypass vulnerability in code-projects Laundry System 1.0 that allows remote attackers to access sensitive d...

Jun 10, 2025
CVE-2025-5512
7.3

This critical vulnerability in shiyi-blog allows attackers to bypass authentication in the administrator backend by exploiting improper authentication...

Jun 3, 2025
CVE-2025-4019
7.3

A critical authentication bypass vulnerability in Novel-Plus allows remote attackers to access the code generation function without authentication. Th...

Apr 28, 2025
CVE-2025-2388
7.3

CVE-2025-2388 is a critical authentication bypass vulnerability in Keytop's roadside parking fee collection system version 2.7.1. Attackers can remote...

Mar 17, 2025
CVE-2025-1104
7.3

This critical vulnerability in D-Link DHP-W310AV powerline adapters allows remote attackers to bypass authentication by spoofing. Attackers can gain u...

Feb 7, 2025
CVE-2024-10173
7.3

This vulnerability allows attackers to bypass authentication in didi DDMQ 1.0's Console Module by manipulating the /;login endpoint. Remote attackers ...

Oct 20, 2024
CVE-2024-45750
7.3

This vulnerability allows remote attackers to execute arbitrary code on affected TheGreenBow VPN clients by sending malformed ECDSA signatures during ...

Sep 25, 2024
CVE-2022-4001
7.3

CVE-2022-4001 is an authentication bypass vulnerability in Motorola Q14 Mesh Router API that allows attackers to access protected API functions withou...

Jul 31, 2024
CVE-2024-37313
7.3

This vulnerability allows attackers to bypass two-factor authentication (2FA) in Nextcloud Server after successfully obtaining valid user credentials....

Jun 14, 2024
CVE-2024-37408
7.3

CVE-2024-37408 is an authentication bypass vulnerability in fprintd fingerprint authentication software. When configured with 'auth sufficient pam_fpr...

Jun 8, 2024
CVE-2024-5732
7.3

This critical vulnerability in Clash for Windows allows remote attackers to bypass authentication on the proxy port component. Attackers can potential...

Jun 7, 2024
CVE-2024-23813
7.3

This vulnerability allows unauthenticated attackers to access REST API endpoints in Polarion ALM's doorsconnector component, potentially enabling remo...

Feb 13, 2024
CVE-2024-1006
7.3

This critical vulnerability in Shanxi Diankeyun Technology NODERP allows attackers to bypass authentication by manipulating cookie parameters (Nod_Use...

Jan 29, 2024
CVE-2023-7210
7.3

This critical vulnerability in OneNav allows attackers to bypass authentication via manipulation of the X-Token parameter in the API endpoint. It enab...

Jan 7, 2024
CVE-2023-5830
7.3

This critical vulnerability in ColumbiaSoft Document Locator allows attackers to bypass authentication via manipulation of the Server parameter in the...

Oct 27, 2023
CVE-2023-4415
7.3

CVE-2023-4415 is an authentication bypass vulnerability in Ruijie RG-EW1200G wireless access points that allows attackers to gain unauthorized access ...

Aug 18, 2023
CVE-2023-0905
7.3

This critical vulnerability in SourceCodester Employee Task Management System 1.0 allows attackers to bypass authentication mechanisms via the changeP...

Feb 18, 2023
CVE-2017-20133
7.3

This vulnerability allows attackers to bypass authentication in Itech Job Portal Script 9.13 by exploiting an unknown flaw in the /admin directory. At...

Jul 16, 2022
CVE-2022-30755
7.3

This vulnerability allows attackers to bypass password confirmation in Samsung's AppLock feature by exploiting implicit intent hijacking. It affects S...

Jul 12, 2022
CVE-2022-1248
7.3

CVE-2022-1248 is a critical authentication bypass vulnerability in SAP Information System 1.0 that allows unauthenticated attackers to create new admi...

Apr 6, 2022
CVE-2022-1084
7.3

CVE-2022-1084 is an authentication bypass vulnerability in SourceCodester One Church Management System 1.0 that allows attackers to bypass authenticat...

Mar 29, 2022
CVE-2021-27451
7.3

Mesa Labs AmegaView versions 3.0 and prior use a weak passcode generation algorithm that can be easily reversed, allowing attackers to calculate valid...

Dec 21, 2021
CVE-2021-22171
7.3

This vulnerability in GitLab Pages allows attackers to steal API tokens through insufficient authentication parameter validation. Attackers can craft ...

Jan 15, 2021
CVE-2025-14097
7.2

A vulnerability in Radiometer medical device software allows remote code execution and unauthorized device management when specific internal condition...

Dec 17, 2025
CVE-2024-9927
7.2

The WooCommerce Order Proposal plugin for WordPress has a privilege escalation vulnerability that allows authenticated attackers with Shop Manager acc...

Oct 23, 2024
CVE-2023-29975
7.2

This vulnerability in pfSense CE 2.6.0 allows attackers to change any user's password without authentication or verification. This affects all pfSense...

Nov 9, 2023
CVE-2023-27091
7.2

CVE-2023-27091 is an improper authentication vulnerability in TeaCMS 2.3.3 that allows attackers to bypass authorization controls via the id and keywo...

Apr 4, 2023
CVE-2021-30028
7.2

SOOTEWAY Wi-Fi Range Extender v1.5 uses default admin credentials for its TELNET service, allowing attackers to remotely access and modify the device ...

May 20, 2022
CVE-2021-0193
7.2

This vulnerability in Intel In-Band Manageability software allows a privileged user to bypass authentication mechanisms via network access, potentiall...

May 12, 2022
CVE-2020-25719
7.2

This vulnerability in Samba's Active Directory Domain Controller allows attackers to bypass Kerberos authentication by exploiting confusion about user...

Feb 18, 2022
CVE-2021-41126
7.2

This vulnerability allows deleted administrator accounts to still authenticate and access the October CMS backend. It affects October CMS v2.0 install...

Oct 6, 2021
CVE-2021-1571
7.2

This CVE describes multiple vulnerabilities in Cisco Small Business 220 Series Smart Switches web management interface that could allow attackers to h...

Jun 16, 2021

About Improper Authentication (CWE-287)

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Our database tracks 783 CVEs classified as CWE-287, with 347 rated critical and 320 rated high severity. The average CVSS score for Improper Authentication vulnerabilities is 8.4.

External reference: View CWE-287 on MITRE CWE →

Monitor Improper Authentication Vulnerabilities

Get alerted when new Improper Authentication CVEs affect your infrastructure.

Start Monitoring Free