When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Volume of CVEs assigned to CWE-287 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
4,507 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-20182CRITICAL May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advi | May 14, 2026 | 10.0 | 99 | YES | YES |
CVE-2025-61882CRITICAL Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14 | Oct 5, 2025 | 9.8 | 99 | YES | YES |
CVE-2022-40684CRITICAL An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version | Oct 18, 2022 | 9.8 | 99 | YES | YES |
CVE-2017-7921CRITICAL An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Bui | May 6, 2017 | 9.8 | 99 | YES | YES |
CVE-2026-50751CRITICAL A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentica | Jun 8, 2026 | 9.3 | 98 | YES | YES |
CVE-2025-61884HIGH Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vu | Oct 12, 2025 | 7.5 | 98 | YES | YES |
CVE-2025-49706MEDIUM Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | Jul 8, 2025 | 6.5 | 98 | YES | YES |
CVE-2024-53704CRITICAL An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | Jan 9, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-7593CRITICAL Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the | Aug 13, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-46805HIGH An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing co | Jan 12, 2024 | 8.2 | 98 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.