The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
Volume of CVEs assigned to CWE-303 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
94 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7593CRITICAL Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the | Aug 13, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-29357CRITICAL Microsoft SharePoint Server Elevation of Privilege Vulnerability | Jun 14, 2023 | 9.8 | 98 | YES | YES |
CVE-2020-8863HIGH This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-882 routers with firmware 1.10B04. Authe | Mar 23, 2020 | 8.8 | 70 | NO | NO |
CVE-2025-13390CRITICAL The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication a | Dec 3, 2025 | 9.8 | 51 | NO | YES |
CVE-2026-46595CRITICAL Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-addre | May 22, 2026 | 10.0 | 44 | NO | NO |
CVE-2022-20695CRITICAL A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication control | Apr 15, 2022 | 10.0 | 44 | NO | NO |
CVE-2026-0073HIGH In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent | May 4, 2026 | 8.8 | 43 | NO | NO |
CVE-2026-12773CRITICAL A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mc | Jun 21, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-41103CRITICAL Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network. | May 12, 2026 | 9.1 | 40 | NO | NO |
CVE-2025-57808HIGH ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can | Sep 2, 2025 | 8.1 | 40 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.