CWE-287: Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

758
Total CVEs
333
Critical
309
High
8.3
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
66
2025
217
2024
134
2023
115
2022
70

Top Affected Vendors

1 Apache 15
2 Qualcomm 12
3 Huawei 11
4 Microsoft 11
5 Debian 10
6 Dlink 9
7 Cisco 9
8 Dell 9
9 Fedoraproject 8
10 Adobe 8

All Improper Authentication CVEs (758)

CVE-2021-22002
9.8

This vulnerability allows attackers to bypass authentication and access sensitive configuration and diagnostic endpoints in VMware Workspace ONE Acces...

Aug 31, 2021
CVE-2021-37417
9.8

This vulnerability allows attackers to bypass CAPTCHA protection in Zoho ManageEngine ADSelfService Plus, potentially enabling brute-force attacks or ...

Aug 30, 2021
CVE-2021-37597
9.8

CVE-2021-37597 is an authentication bypass vulnerability in WP Cerber security plugin for WordPress that allows attackers to bypass multi-factor authe...

Aug 19, 2021
CVE-2021-24527
9.8

This vulnerability in the Profile Builder WordPress plugin allows any user to reset the administrator password without proper authorization, potential...

Aug 16, 2021
CVE-2014-9320
9.8

CVE-2014-9320 is a critical vulnerability in SAP BusinessObjects Edge 4.1 that allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_T...

Aug 9, 2021
CVE-2020-4821
9.8

This vulnerability allows attackers to bypass authentication in IBM InfoSphere Data Replication and Change Data Capture for z/OS by using an empty pas...

Jul 16, 2021
CVE-2021-34690
9.8

CVE-2021-34690 allows unauthenticated remote attackers to bypass cloud authentication in iDrive RemotePC for Windows, enabling them to connect to and ...

Jul 15, 2021
CVE-2021-21994
9.8

CVE-2021-21994 is an authentication bypass vulnerability in SFCB (Small Footprint CIM Broker) used in VMware ESXi. An attacker with network access to ...

Jul 13, 2021
CVE-2021-20776
9.8

CVE-2021-20776 is an authentication bypass vulnerability in specific Sharp and Aterm routers that allows attackers to execute arbitrary commands via t...

Jul 7, 2021
CVE-2021-35029
9.8

This authentication bypass vulnerability in Zyxel security appliances allows remote attackers to execute arbitrary commands without valid credentials....

Jul 2, 2021
CVE-2021-30648
9.8

CVE-2021-30648 is an authentication bypass vulnerability in Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles. Unauthenticate...

Jun 30, 2021
CVE-2021-21998
9.8

CVE-2021-21998 is an authentication bypass vulnerability in VMware Carbon Black App Control that allows attackers with network access to the managemen...

Jun 23, 2021
CVE-2021-27610
9.8

This vulnerability in SAP NetWeaver ABAP Server and ABAP Platform allows improper authentication due to inconsistent formatting of RFC user informatio...

Jun 16, 2021
CVE-2021-23847
9.8

This critical vulnerability in Bosch IP cameras allows unauthenticated remote attackers to extract sensitive information or modify camera settings by ...

Jun 9, 2021
CVE-2021-31251
9.8

This CVE describes an authentication bypass vulnerability in CHIYU Technology's telnet server implementation for specific IoT converter devices. Attac...

Jun 4, 2021
CVE-2021-23008
9.8

This vulnerability allows attackers to bypass Active Directory authentication on BIG-IP APM systems by spoofing Kerberos authentication responses. Aff...

May 10, 2021
CVE-2021-28152
9.8

Hongdian H8922 devices have a backdoor telnet service on port 5188 with hardcoded superuser credentials (root:superzxmn). This allows attackers to gai...

May 6, 2021
CVE-2021-32030
9.8

This vulnerability allows unauthenticated attackers to bypass authentication on ASUS GT-AC2900 and Lyra Mini routers by sending specially crafted inpu...

May 6, 2021
CVE-2020-19111
9.8

This vulnerability allows remote attackers to bypass authentication in Online Book Store v1.0 via the admin_verify.php file, enabling unauthorized acc...

May 6, 2021
CVE-2021-27651
9.8

CVE-2021-27651 is an authentication bypass vulnerability in Pega Infinity that allows attackers to reset passwords for local accounts without proper a...

Apr 29, 2021
CVE-2021-20020
9.8

CVE-2021-20020 is a critical authentication bypass vulnerability in SonicWall Global Management System (GMS) that allows remote unauthenticated attack...

Apr 10, 2021
CVE-2021-22507
9.8

CVE-2021-22507 is an authentication bypass vulnerability in Micro Focus Operations Bridge Manager that allows remote attackers to gain unauthorized ac...

Apr 8, 2021
CVE-2021-24175
9.8

This critical vulnerability in the Plus Addons for Elementor WordPress plugin allows unauthenticated attackers to bypass authentication completely. At...

Apr 5, 2021
CVE-2021-29012
9.8

CVE-2021-29012 is a critical authentication bypass vulnerability in DMA Softlab Radius Manager 4.4.0 where the same static session cookie is assigned ...

Apr 2, 2021
CVE-2021-24148
9.8

This vulnerability allows unauthenticated attackers to bypass authentication in the MStore API WordPress plugin by exploiting a business logic flaw in...

Mar 18, 2021
CVE-2021-25315
9.8

This vulnerability allows local attackers to execute arbitrary code via Salt without valid credentials due to improper authentication. It affects SUSE...

Mar 3, 2021
CVE-2021-25281
9.8

This vulnerability in SaltStack Salt allows unauthenticated remote attackers to execute arbitrary wheel modules on the Salt master via salt-api. The w...

Feb 27, 2021
CVE-2020-10539
9.8

This vulnerability allows authentication bypass in Epikur software by using a hardcoded backdoor password. Any attacker who discovers this password ca...

Feb 5, 2021
CVE-2020-17523
9.8

CVE-2020-17523 is an authentication bypass vulnerability in Apache Shiro when used with Spring. Attackers can craft HTTP requests to bypass authentica...

Feb 3, 2021
CVE-2020-15835
9.8

This vulnerability allows attackers with a specific private key to authenticate as root on affected Mofi routers without knowing the actual root passw...

Feb 1, 2021
CVE-2020-27488
9.8

Loxone Miniserver devices with vulnerable firmware cannot properly authenticate with cloud services, allowing attackers to spoof devices and potential...

Jan 13, 2021
CVE-2020-5633
9.8

This critical vulnerability in NEC server BMC firmware allows remote attackers to bypass authentication entirely. Attackers can then access/modify BMC...

Jan 13, 2021
CVE-2012-10001
9.8

The Limit Login Attempts WordPress plugin before version 1.7.1 fails to clear authentication cookies when locking out users after failed login attempt...

Jan 6, 2021
CVE-2020-25848
9.8

CVE-2020-25848 is an authentication bypass vulnerability in HGiga MailSherlock that allows remote attackers to gain administrative privileges using we...

Dec 31, 2020
CVE-2020-26030
9.8

This vulnerability allows attackers to bypass authentication in Zammad's SSO endpoint by sending a crafted header when SSO is not configured. Attacker...

Dec 28, 2020
CVE-2020-24675
9.8

CVE-2020-24675 is an authentication bypass vulnerability in ABB's S+ Operations and S+ History software that allows unauthenticated attackers to injec...

Dec 22, 2020
CVE-2020-27780
9.8

This Linux-PAM vulnerability allows authentication bypass for non-existent users with empty passwords, effectively granting root access. It affects Li...

Dec 18, 2020
CVE-2020-8465
9.8

This vulnerability in Trend Micro InterScan Web Security Virtual Appliance allows an attacker to combine CSRF bypass and authentication bypass vulnera...

Dec 17, 2020
CVE-2020-4747
9.8

CVE-2020-4747 is an authentication bypass vulnerability in IBM Connect:Direct for UNIX that allows local or remote users to obtain authenticated CLI s...

Dec 15, 2020
CVE-2020-29563
9.8

This vulnerability allows unauthenticated attackers to bypass authentication on Western Digital My Cloud OS 5 devices, gaining administrative access t...

Dec 12, 2020
CVE-2020-28970
9.8

This vulnerability allows unauthenticated attackers to bypass authentication on Western Digital My Cloud OS 5 devices and execute privileged commands....

Dec 1, 2020
CVE-2020-29127
9.8

This vulnerability allows authentication bypass on Fujitsu Eternus Storage DX200 S4 devices. After a root user logs into the web portal, attackers can...

Nov 30, 2020
CVE-2019-20933
9.8

CVE-2019-20933 is an authentication bypass vulnerability in InfluxDB where JWT tokens with empty shared secrets are incorrectly accepted as valid. Thi...

Nov 19, 2020
CVE-2020-28638
9.8

CVE-2020-28638 is a critical authentication bypass vulnerability in Tomb's password handling. When pinentry-curses is used with a non-empty DISPLAY en...

Nov 13, 2020
CVE-2020-26168
9.8

This vulnerability allows authentication bypass in Hazelcast IMDG Enterprise and Jet Enterprise when using LDAP authentication with system-user-dn con...

Nov 9, 2020
CVE-2020-26542
9.8

This vulnerability allows authentication bypass in MongoDB Simple LDAP plugin for Percona Server when using SimpleLDAP authentication with Microsoft A...

Nov 9, 2020
CVE-2020-25592
9.8

CVE-2020-25592 is an authentication bypass vulnerability in SaltStack Salt's REST API (salt-netapi) that allows attackers to execute arbitrary command...

Nov 6, 2020
CVE-2020-17510
9.8

CVE-2020-17510 is an authentication bypass vulnerability in Apache Shiro when used with Spring. A specially crafted HTTP request can bypass authentica...

Nov 5, 2020
CVE-2020-7197
9.8

CVE-2020-7197 is a critical authentication bypass vulnerability in HPE StoreServ Management Console (SSMC) 3.7.0.0 that allows remote attackers to gai...

Oct 26, 2020
CVE-2020-24629
9.8

CVE-2020-24629 is an authentication bypass vulnerability in HPE Intelligent Management Center's urlaccesscontroller component. Attackers can remotely ...

Oct 19, 2020

About Improper Authentication (CWE-287)

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Our database tracks 758 CVEs classified as CWE-287, with 333 rated critical and 309 rated high severity. The average CVSS score for Improper Authentication vulnerabilities is 8.3.

External reference: View CWE-287 on MITRE CWE →

Monitor Improper Authentication Vulnerabilities

Get alerted when new Improper Authentication CVEs affect your infrastructure.

Start Monitoring Free