CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2025-61673
HIGH
Karapace 5.0.0-5.0.1 - Unauthenticated Authentication Bypass via Missing Authorization Header
CVSS 8.6
CVE-2025-6388
CRITICAL
Spirit Framework plugin - Auth Bypass
CVSS 9.8
CVE-2025-10653
HIGH
Unspecified Product <Version> - Info Disclosure
CVSS 8.6
CVE-2025-22862
MEDIUM
FortiOS 7.0.6-7.4.7 and FortiProxy 7.0.5-7.6.2 - Authenticated Privilege Escalation via Automation Stitch Webhook Action
CVSS 6.7
CVE-2025-61733
HIGH
Apache Kylin 4.0.0-5.0.2 - Authentication Bypass Using an Alternate Path or Channel
CVSS 7.5
CVE-2025-10538
HIGH
LG Innotek Camera Models LND7210 and LNV7210R - Authentication Bypass
CVE-2025-7038
HIGH
LatePoint Calendar Booking Plugin <= 5.1.94 - Unauthenticated Authentication Bypass
CVSS 8.2
CVE-2025-5955
HIGH
Service Finder SMS System <2.0.0 - Auth Bypass
CVSS 8.1
CVE-2025-10531
MEDIUM
Firefox <143 - Privilege Escalation
CVSS 5.4
CVE-2025-8359
CRITICAL
AdForest theme <6.0.9 - Auth Bypass
CVSS 9.8
CVE-2025-57819
CRITICAL
KEV
FreePBX 15.0-15.0.65 - Unauthenticated Authentication Bypass and Remote Code Execution
CVSS 9.8
CVE-2025-54738
CRITICAL
NooTheme Jobmonster <4.7.9 - Auth Bypass
CVSS 9.8
CVE-2025-54725
CRITICAL
Golo <= 1.7.0 - Authentication Bypass via Alternate Path
CVSS 9.8
CVE-2025-34520
CRITICAL
Arcserve UDP < 10.2 - Unauthenticated Authentication Bypass via Request Parameter Manipulation
CVSS 9.8
CVE-2025-5821
CRITICAL
Case Theme User <1.0.3 - Auth Bypass
CVSS 9.8
CVE-2025-5060
HIGH
Bravis User <= 1.0.1 - Authentication Bypass via Facebook Login Callback
CVSS 8.1
CVE-2025-7642
CRITICAL
Simpler Checkout 0.7.0-1.1.9 - Auth Bypass
CVSS 9.8
CVE-2025-55623
MEDIUM
Reolink v4.54.0.4.20250526 - Auth Bypass
CVSS 5.4
CVE-2025-50904
CRITICAL
WinterChenS my-site < 2025-06-11 - Unauthenticated Authentication Bypass via /admin/ API
CVSS 9.8
CVE-2025-27129
CRITICAL
Tenda AC6 V5.0 V02.03.01.110 - Auth Bypass
CVSS 9.8
CVE-2025-24496
HIGH
Tenda AC6 V5.0 V02.03.01.110 - Information Disclosure via /goform/getproductInfo
CVSS 7.5
CVE-2025-54713
CRITICAL
Taxi Booking Manager for WooCommerce <1.3.0 - Auth Bypass
CVSS 9.8
CVE-2025-52338
MEDIUM
LogicData eCommerce Framework <5.0.9.7000 - Auth Bypass
CVSS 5.3
CVE-2025-3639
LOW
Liferay Portal 7.3.0-7.4.3.132 & DXP - Unauthenticated Authentication Bypass via POST to GET
CVE-2025-8995
CRITICAL
Authenticator Login < 2.1.4 - Authentication Bypass via Alternate Path
CVSS 9.8
Details
Vulnerabilities
612