CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2025-1909
CRITICAL
BuddyBoss Platform Pro <2.7.01 - Auth Bypass
CVSS 9.8
CVE-2025-47244
HIGH
ProGet >=5 <2024.22 - Unauthenticated Denial of Service via C# Reflection Layer
CVSS 7.3
CVE-2025-24206
HIGH
iPadOS < 17.7.6 - Authentication Bypass via Improved State Management
CVSS 7.7
CVE-2025-2492
CRITICAL
ASUS Router AiCloud - Authentication Bypass via Crafted Request
CVE-2025-39535
HIGH
appsbd Vitepos <3.1.7 - Auth Bypass
CVSS 7.2
CVE-2025-32357
MEDIUM
Zammad 6.4.0-6.4.1 - Authenticated Unauthorized Knowledge Base Content Access via API
CVSS 4.3
CVE-2025-31095
CRITICAL
Material Dashboard <1.4.5 - Auth Bypass
CVSS 9.8
CVE-2025-22277
HIGH
appsbd Vitepos <3.1.4 - Auth Bypass
CVSS 8.8
CVE-2025-24095
HIGH
iPadOS < 18.4 - Authentication Bypass via Privacy Preferences
CVSS 7.6
CVE-2025-31694
HIGH
Drupal Two-factor Authentication < 1.10.0 - Authentication Bypass via Forceful Browsing
CVSS 8.1
CVE-2025-22230
HIGH
VMware Tools for Windows - Privilege Escalation
CVSS 7.8
CVE-2025-2747
CRITICAL
KEV
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006)
CVSS 9.8
CVE-2025-2746
CRITICAL
KEV
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)
CVSS 9.8
CVE-2025-30112
HIGH
70mai Dash Cam 1S - Unauthenticated Authentication Bypass via Direct Network API Access
CVSS 7.1
CVE-2025-2080
CRITICAL
Optigo Networks Visual BACnet Capture Tool/Optigo Visual Networks C...
CVE-2025-29996
HIGH
Rising Technosoft CAP back office application < 2.0.4 - Two-Factor Authentication Bypass via API Request Manipulation
CVE-2025-1315
CRITICAL
Sfwebservice Injob < 3.5.1 - Missing Authentication
CVSS 9.8
CVE-2025-0749
HIGH
Homey < 2.4.3 - Unauthenticated Authentication Bypass via Empty Verification ID
CVSS 8.1
CVE-2025-1515
CRITICAL
WP Real Estate Manager <2.8 - Auth Bypass
CVSS 9.8
CVE-2025-27658
CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Authentication Bypass
CVSS 9.8
CVE-2025-24846
HIGH
FutureNet AS-250 < 1.14.0 - Authentication Bypass via Crafted Request
CVSS 7.5
CVE-2025-1671
CRITICAL
Academist Membership <1.1.6 - Privilege Escalation
CVSS 9.8
CVE-2025-1638
CRITICAL
Alloggio Membership <1.0.2 - Auth Bypass
CVSS 9.8
CVE-2025-1564
CRITICAL
SetSail Membership <1.0.3 - Auth Bypass
CVSS 9.8
CVE-2025-0159
CRITICAL
IBM Storage Virtualize Unauthenticated Authentication Bypass via RPCAdapter Endpoint
CVSS 9.1
Details
Vulnerabilities
612