Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-287

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

4,507
Assigned CVEs
18th
Commonality Rank
7.7
Avg CVSS
1.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-287 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 1999
27 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

4,507 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-20182CRITICAL
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advi
May 14, 202610.099YESYES
CVE-2025-61882CRITICAL
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14
Oct 5, 20259.899YESYES
CVE-2022-40684CRITICAL
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version
Oct 18, 20229.899YESYES
CVE-2017-7921CRITICAL
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Bui
May 6, 20179.899YESYES
CVE-2026-50751CRITICAL
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentica
Jun 8, 20269.398YESYES
CVE-2025-61884HIGH
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vu
Oct 12, 20257.598YESYES
CVE-2025-49706MEDIUM
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Jul 8, 20256.598YESYES
CVE-2024-53704CRITICAL
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Jan 9, 20259.898YESYES
CVE-2024-7593CRITICAL
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the
Aug 13, 20249.898YESYES
CVE-2023-46805HIGH
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing co
Jan 12, 20248.298YESYES
View all 4,507 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
13%
19%
5.0-5.9
12%
16%
6.0-6.9
23%
26%
7.0-7.9
14%
11%
8.0-8.9
31%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
43 CVEs
1.0% of CVEs· 90th percentile
Metasploit
88 CVEs
2.0% of CVEs· 93rd percentile
Nuclei
111 CVEs
2.5% of CVEs· 91st percentile
ExploitDB
342 CVEs
7.6% of CVEs· 96th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products