CWE-287

High likelihood

Improper Authentication

Parent: CWE-284 - Improper Access Control

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,320 vulnerabilities with CWE-287
CVE-2025-55340 HIGH
Windows Remote Desktop - Privilege Escalation
CVSS 7.0
CVE-2025-53845 MEDIUM
Fortinet FortiAnalyzer <7.6.3 - Info Disclosure
CVSS 6.5
CVE-2025-9064 CRITICAL
FactoryTalk View Machine Edition - Path Traversal
CVSS 9.1
CVE-2025-9063 CRITICAL
FactoryTalk View Machine Edition - Auth Bypass
CVSS 9.8
CVE-2025-9265 CRITICAL
Kiloview NDI N30 < 2.02.246 - Unauthenticated Broken Authorization
CVE-2025-11661 HIGH
oranbyte School Management System - Improper Authentication
CVSS 7.3
CVE-2025-11633 LOW
Furbo 360 Dog Camera <036 & Furbo Mini <074 - Improper Certificate Validation
CVSS 3.7
CVE-2025-61884 HIGH KEV
Oracle Configurator 12.2.3-12.2.14 - Unauthenticated CRLF Injection via Runtime UI
CVSS 7.5
CVE-2025-60306 CRITICAL
code-projects Simple Car Rental System 1.0 - Auth Bypass
CVSS 9.9
CVE-2025-11529 HIGH
ChurchCRM < 5.19.0 - Authentication Bypass in AuthMiddleware
CVSS 7.3
CVE-2025-11192 HIGH
Extreme Networks Fabric Engine <9.3 - Privilege Escalation
CVSS 8.6
CVE-2025-11287 HIGH
samanhappy MCPHub <0.9.10 - Auth Bypass
CVSS 7.3
CVE-2025-61882 CRITICAL KEV
Oracle Concurrent Processing 12.2.3-12.2.14 - Unauthenticated Takeover
CVSS 9.8
CVE-2025-61679 HIGH
anyquery < 0.4.4 - Unauthenticated Exposure of Sensitive Integration Data via HTTP Server
CVSS 7.7
CVE-2025-54154 MEDIUM
QNAP Authenticator 1.3.0-1.3.1.1226 - Improper Authentication
CVSS 6.8
CVE-2025-61665 HIGH
WeGIA < 3.5.0 - Unauthenticated Sensitive Information Exposure via get_relatorios_socios.php Endpoint
CVSS 7.5
CVE-2025-41064 CRITICAL
GTT OpenSIAC - Improper Authentication via Cl@ve Impersonation
CVE-2025-11130 HIGH
iHongRen pptp-vpn 1.0/1.0.1 - Missing Authentication
CVSS 8.4
CVE-2025-59934 CRITICAL
formbricks < 4.0.1 - Unauthenticated Authentication Bypass via JWT Signature Verification Missing
CVSS 9.4
CVE-2025-20160 HIGH
Cisco IOS Software - Info Disclosure
CVSS 8.1
CVE-2025-10906 HIGH
Magnetism Studios Endurance <3.3.0 - Use After Free
CVSS 8.4
CVE-2025-0672 LOW
WSO2 Identity Server - Authentication Bypass via FIDO Registration Data
CVSS 3.3
CVE-2025-0663 MEDIUM
WSO2 Identity Server - Cross-Tenant Authentication Bypass via Adaptive Authentication Cookie Forgery
CVSS 6.8
CVE-2025-9965 CRITICAL
Novakon P series < P-2.0.05 - Unauthenticated Arbitrary Application Upload/Download
CVE-2025-57434 HIGH
Creacast Creabox Manager - Improper Authentication via Password Prefix Bypass
CVSS 8.8
Details
Vulnerabilities 4,320
Exploit Likelihood High