CWE-287: Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

758
Total CVEs
333
Critical
309
High
8.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
66
2025
217
2024
134
2023
115
2022
70

Top Affected Vendors

1 Apache 15
2 Qualcomm 12
3 Huawei 11
4 Microsoft 11
5 Debian 10
6 Dlink 9
7 Cisco 9
8 Dell 9
9 Fedoraproject 8
10 Adobe 8

All Improper Authentication CVEs (758)

CVE-2023-30869
9.8

This vulnerability allows unauthenticated attackers to gain administrative privileges on WordPress sites running the Easy Digital Downloads plugin. At...

May 2, 2023
CVE-2022-35898
9.8

CVE-2022-35898 is an authentication bypass vulnerability in OpenText BizManager that allows any authenticated user to change passwords for any other u...

May 1, 2023
CVE-2023-2297
9.8

The Profile Builder WordPress plugin up to version 3.9.0 uses plaintext password reset keys instead of hashed values, allowing attackers to reset user...

Apr 27, 2023
CVE-2021-40506
9.8

This vulnerability affects the OR1200 processor's ALU unit, where the overflow flag is not updated correctly for msb and mac instructions. This can ca...

Apr 18, 2023
CVE-2023-24831
9.8

CVE-2023-24831 is an authentication bypass vulnerability in Apache IoTDB Grafana Connector that allows attackers to log in without proper credentials....

Apr 17, 2023
CVE-2023-2027
9.8

The ZM Ajax Login & Register WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existi...

Apr 15, 2023
CVE-2022-45173
9.8

This vulnerability allows attackers to bypass two-factor authentication in LIVEBOX Collaboration vDesk by manipulating client-side verification of TOT...

Apr 14, 2023
CVE-2023-28121
9.8

CVE-2023-28121 is an authentication bypass vulnerability in WooCommerce Payments plugin for WordPress that allows unauthenticated attackers to imperso...

Apr 12, 2023
CVE-2023-28862
9.8

This vulnerability in LemonLDAP::NG allows attackers to bypass two-factor authentication (2FA) by exploiting weak session ID generation in the AuthBas...

Mar 31, 2023
CVE-2023-28398
9.8

CVE-2023-28398 allows unauthenticated attackers to create accounts and bypass authentication on Osprey Pump Controller version 1.01, gaining unauthori...

Mar 28, 2023
CVE-2023-28609
9.8

CVE-2023-28609 is an authentication bypass vulnerability in Ansible Semaphore's API authentication handler. It allows attackers to bypass authenticati...

Mar 18, 2023
CVE-2023-28461
9.8

CVE-2023-28461 is a critical remote code execution vulnerability in Array Networks AG Series and vxAG SSL VPN gateways. Attackers can exploit this wit...

Mar 15, 2023
CVE-2023-1327
9.8

CVE-2023-1327 is an authentication bypass vulnerability in Netgear RAX30 routers that allows unauthenticated attackers to reset the admin password and...

Mar 14, 2023
CVE-2023-24093
9.8

This critical vulnerability in H3C A210-G wireless access points allows attackers to bypass authentication without requiring any password. Attackers c...

Feb 22, 2023
CVE-2022-30270
9.8

The Motorola ACE1000 RTU has five preconfigured accounts with default credentials, including two undocumented accounts. This allows attackers to gain ...

Jul 26, 2022
CVE-2021-40874
9.8

This vulnerability allows authentication bypass in LemonLDAP::NG when using the RESTServer plugin with Kerberos authentication combined with another m...

Jul 18, 2022
CVE-2022-2197
9.8

CVE-2022-2197 is an authentication bypass vulnerability in certain industrial control system devices. Attackers with network access to the web interfa...

Jun 30, 2022
CVE-2021-41506
9.8

This CVE describes a critical backdoor vulnerability in multiple Xiaongmai DVR/NVR/IP camera models and firmware versions. The vulnerability exists du...

Jun 30, 2022
CVE-2022-33750
9.8

CVE-2022-33750 is an authentication bypass vulnerability in CA Automic Automation agents that allows remote attackers to execute arbitrary commands wi...

Jun 16, 2022
CVE-2022-20798
9.8

This vulnerability allows unauthenticated remote attackers to bypass LDAP authentication on Cisco Secure Email and Web Manager (formerly SMA) and Cisc...

Jun 15, 2022
CVE-2022-28106
9.8

Online Sports Complex Booking System v1.0 contains an authentication bypass vulnerability that allows attackers to take over user accounts via crafted...

May 20, 2022
CVE-2019-12254
9.8

This vulnerability allows unauthenticated attackers to change application settings in Tecson Tankspion and GOKs SmartBox 4 products by accessing a spe...

May 6, 2022
CVE-2022-26562
9.8

This authentication bypass vulnerability in Kopano Core and Zarafa Collaboration Platform allows attackers to authenticate with expired user accounts ...

Apr 1, 2022
CVE-2022-23795
9.8

This vulnerability in Joomla! allows account takeover under specific circumstances because user authentication rows aren't properly bound to authentic...

Mar 30, 2022
CVE-2022-0342
9.8

This authentication bypass vulnerability in Zyxel firewall CGI programs allows attackers to circumvent web authentication and gain administrative acce...

Mar 28, 2022
CVE-2021-31326
9.8

This vulnerability allows unauthenticated attackers to remotely reset D-Link DIR-816 A2 routers to factory defaults via a crafted HTTP request. Attack...

Mar 24, 2022
CVE-2022-0730
9.8

CVE-2022-0730 is an authentication bypass vulnerability in Cacti that allows attackers to gain unauthorized access under specific LDAP configurations....

Mar 3, 2022
CVE-2022-24259
9.8

CVE-2022-24259 is an authentication bypass vulnerability in Voipmonitor GUI's cdr.php component that allows unauthenticated attackers to escalate priv...

Feb 4, 2022
CVE-2021-43394
9.8

This vulnerability allows attackers to bypass LDAP authentication in Unisys OS 2200 Messaging Integration Services due to improper password validation...

Jan 24, 2022
CVE-2022-23178
9.8

CVE-2022-23178 allows unauthenticated attackers to retrieve administrative credentials from Crestron HD-MD4X2-4K-E HDMI switchers by accessing aj.html...

Jan 15, 2022
CVE-2021-34993
9.8

CVE-2021-34993 is an authentication bypass vulnerability in Commvault CommCell's CVSearchService that allows remote attackers to access the system wit...

Jan 13, 2022
CVE-2021-33046
9.8

This vulnerability allows attackers to reset passwords on Dahua devices through improper access control in the password reset process. It affects Dahu...

Jan 13, 2022
CVE-2021-45389
9.8

This vulnerability allows attackers to bypass authentication in StarWind SAN/NAS and Command Center by injecting self-signed JWT tokens into the updat...

Jan 4, 2022
CVE-2021-45890
9.8

CVE-2021-45890 is an authentication bypass vulnerability in AuthGuard's BasicAuthProvider that allows authentication using inactive user identifiers. ...

Dec 27, 2021
CVE-2021-44676
9.8

CVE-2021-44676 is an authentication bypass vulnerability in Zoho ManageEngine Access Manager Plus that allows unauthenticated attackers to view sensit...

Dec 20, 2021
CVE-2021-4073
9.8

CVE-2021-4073 is an authentication bypass vulnerability in the RegistrationMagic WordPress plugin that allows unauthenticated attackers to log in as a...

Dec 14, 2021
CVE-2021-43931
9.8

CVE-2021-43931 is an authentication bypass vulnerability in WebHMI portal software that allows attackers to circumvent authentication mechanisms and g...

Dec 6, 2021
CVE-2021-43786
9.8

CVE-2021-43786 is an authentication bypass vulnerability in NodeBB forum software where incorrect token verification logic allowed attackers to gain m...

Nov 29, 2021
CVE-2021-37580
9.8

This vulnerability allows attackers to bypass authentication in Apache ShenYu Admin by exploiting incorrect JWT implementation. It affects Apache Shen...

Nov 16, 2021
CVE-2021-31349
9.8

This CVE describes an authentication bypass vulnerability in Juniper Networks 128 Technology Session Smart Router where an attacker can use an interna...

Oct 19, 2021
CVE-2021-37123
9.8

This vulnerability allows attackers to bypass authentication in Hero-CT060 devices and perform unauthorized operations. It affects all Hero-CT060 devi...

Oct 11, 2021
CVE-2021-39226
9.8

This vulnerability in Grafana allows unauthenticated or authenticated users to view and delete the snapshot with the lowest database key via specific ...

Oct 5, 2021
CVE-2021-35296
9.8

This vulnerability allows attackers to bypass authentication on PTCL HG150-Ub v3.0 routers by manipulating cookie values and response paths. Attackers...

Oct 4, 2021
CVE-2021-20578
9.8

This vulnerability allows attackers to perform unauthorized actions in IBM Cloud Pak for Security due to improper authentication controls. Attackers c...

Sep 30, 2021
CVE-2021-35943
9.8

CVE-2021-35943 allows externally managed users in Couchbase Server to authenticate with empty passwords, violating RFC4513 authentication requirements...

Sep 29, 2021
CVE-2021-31917
9.8

This vulnerability allows attackers to bypass authentication on REST endpoints when DIGEST authentication is configured in Red Hat DataGrid and Infini...

Sep 21, 2021
CVE-2021-41317
9.8

CVE-2021-41317 is an authentication bypass vulnerability in XSS Hunter Express that allows unauthenticated attackers to access administrative paths. T...

Sep 17, 2021
CVE-2021-41303
9.8

CVE-2021-41303 is an authentication bypass vulnerability in Apache Shiro when used with Spring Boot. A specially crafted HTTP request can allow attack...

Sep 17, 2021
CVE-2021-33044
9.8

CVE-2021-33044 is an authentication bypass vulnerability in certain Dahua security products that allows attackers to gain unauthorized access by sendi...

Sep 15, 2021
CVE-2021-40350
9.8

CVE-2021-40350 is an authentication bypass vulnerability in Christie Digital DWU850-GS projectors that allows attackers to perform any administrative ...

Sep 1, 2021

About Improper Authentication (CWE-287)

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Our database tracks 758 CVEs classified as CWE-287, with 333 rated critical and 309 rated high severity. The average CVSS score for Improper Authentication vulnerabilities is 8.3.

External reference: View CWE-287 on MITRE CWE →

Monitor Improper Authentication Vulnerabilities

Get alerted when new Improper Authentication CVEs affect your infrastructure.

Start Monitoring Free