CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
569 vulnerabilities with CWE-288
CVE-2025-47710
HIGH
miniorange_2fa 5.0.0-5.1.9 - Authentication Bypass via Alternate Path
CVSS 7.4
CVE-2025-47707
HIGH
miniorange_2fa 5.0.0-5.2.0 - Authentication Bypass via Alternate Path
CVSS 7.5
CVE-2025-3932
MEDIUM
Thunderbird < 128.10.1, < 138.0.1 - XSS
CVSS 6.5
CVE-2025-4427
MEDIUM
KEV
Ivanti Endpoint Manager Mobile <= 12.5.0.0 - Unauthenticated Authentication Bypass via API
CVSS 5.3
CVE-2025-22462
CRITICAL
Ivanti Neurons for ITSM < 2023.4, 2024.2, 2024.3 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2025-40581
HIGH
SCALANCE LPE9403 - Authentication Bypass via SINEMA Remote Connect Edge Client
CVSS 7.1
CVE-2025-0549
MEDIUM
GitLab CE/EE <17.9.8, <17.10.6, <17.11.2 - Auth Bypass
CVSS 6.8
CVE-2025-3844
CRITICAL
PeproDev Ultimate Profile Solutions <7.5.2 - Auth Bypass
CVSS 9.8
CVE-2025-45607
CRITICAL
itranswarp v2.19 - Authentication Bypass via /manage/ Request
CVSS 9.8
CVE-2025-1909
CRITICAL
BuddyBoss Platform Pro <2.7.01 - Auth Bypass
CVSS 9.8
CVE-2025-47244
HIGH
ProGet >=5 <2024.22 - Unauthenticated Denial of Service via C# Reflection Layer
CVSS 7.3
CVE-2025-24206
HIGH
iPadOS < 17.7.6 - Authentication Bypass via Improved State Management
CVSS 7.7
CVE-2025-2492
CRITICAL
ASUS Router AiCloud - Authentication Bypass via Crafted Request
CVE-2025-39535
HIGH
appsbd Vitepos <3.1.7 - Auth Bypass
CVSS 7.2
CVE-2025-32357
MEDIUM
Zammad 6.4.0-6.4.1 - Authenticated Unauthorized Knowledge Base Content Access via API
CVSS 4.3
CVE-2025-31095
CRITICAL
Material Dashboard <1.4.5 - Auth Bypass
CVSS 9.8
CVE-2025-22277
HIGH
appsbd Vitepos <3.1.4 - Auth Bypass
CVSS 8.8
CVE-2025-24095
HIGH
iPadOS < 18.4 - Authentication Bypass via Privacy Preferences
CVSS 7.6
CVE-2025-31694
HIGH
Drupal Two-factor Authentication < 1.10.0 - Authentication Bypass via Forceful Browsing
CVSS 8.1
CVE-2025-22230
HIGH
VMware Tools for Windows - Privilege Escalation
CVSS 7.8
CVE-2025-2747
CRITICAL
KEV
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006)
CVSS 9.8
CVE-2025-2746
CRITICAL
KEV
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)
CVSS 9.8
CVE-2025-30112
HIGH
70mai Dash Cam 1S - Unauthenticated Authentication Bypass via Direct Network API Access
CVSS 7.1
CVE-2025-2080
CRITICAL
Optigo Networks Visual BACnet Capture Tool/Optigo Visual Networks C...
CVE-2025-29996
HIGH
Rising Technosoft CAP back office application < 2.0.4 - Two-Factor Authentication Bypass via API Request Manipulation
Details
Vulnerabilities
569