CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2025-1909 CRITICAL
BuddyBoss Platform Pro <2.7.01 - Auth Bypass
CVSS 9.8
CVE-2025-47244 HIGH
ProGet >=5 <2024.22 - Unauthenticated Denial of Service via C# Reflection Layer
CVSS 7.3
CVE-2025-24206 HIGH
iPadOS < 17.7.6 - Authentication Bypass via Improved State Management
CVSS 7.7
CVE-2025-2492 CRITICAL
ASUS Router AiCloud - Authentication Bypass via Crafted Request
CVE-2025-39535 HIGH
appsbd Vitepos <3.1.7 - Auth Bypass
CVSS 7.2
CVE-2025-32357 MEDIUM
Zammad 6.4.0-6.4.1 - Authenticated Unauthorized Knowledge Base Content Access via API
CVSS 4.3
CVE-2025-31095 CRITICAL
Material Dashboard <1.4.5 - Auth Bypass
CVSS 9.8
CVE-2025-22277 HIGH
appsbd Vitepos <3.1.4 - Auth Bypass
CVSS 8.8
CVE-2025-24095 HIGH
iPadOS < 18.4 - Authentication Bypass via Privacy Preferences
CVSS 7.6
CVE-2025-31694 HIGH
Drupal Two-factor Authentication < 1.10.0 - Authentication Bypass via Forceful Browsing
CVSS 8.1
CVE-2025-22230 HIGH
VMware Tools for Windows - Privilege Escalation
CVSS 7.8
CVE-2025-2747 CRITICAL KEV
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006)
CVSS 9.8
CVE-2025-2746 CRITICAL KEV
Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)
CVSS 9.8
CVE-2025-30112 HIGH
70mai Dash Cam 1S - Unauthenticated Authentication Bypass via Direct Network API Access
CVSS 7.1
CVE-2025-2080 CRITICAL
Optigo Networks Visual BACnet Capture Tool/Optigo Visual Networks C...
CVE-2025-29996 HIGH
Rising Technosoft CAP back office application < 2.0.4 - Two-Factor Authentication Bypass via API Request Manipulation
CVE-2025-1315 CRITICAL
Sfwebservice Injob < 3.5.1 - Missing Authentication
CVSS 9.8
CVE-2025-0749 HIGH
Homey < 2.4.3 - Unauthenticated Authentication Bypass via Empty Verification ID
CVSS 8.1
CVE-2025-1515 CRITICAL
WP Real Estate Manager <2.8 - Auth Bypass
CVSS 9.8
CVE-2025-27658 CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Authentication Bypass
CVSS 9.8
CVE-2025-24846 HIGH
FutureNet AS-250 < 1.14.0 - Authentication Bypass via Crafted Request
CVSS 7.5
CVE-2025-1671 CRITICAL
Academist Membership <1.1.6 - Privilege Escalation
CVSS 9.8
CVE-2025-1638 CRITICAL
Alloggio Membership <1.0.2 - Auth Bypass
CVSS 9.8
CVE-2025-1564 CRITICAL
SetSail Membership <1.0.3 - Auth Bypass
CVSS 9.8
CVE-2025-0159 CRITICAL
IBM Storage Virtualize Unauthenticated Authentication Bypass via RPCAdapter Endpoint
CVSS 9.1
Details
Vulnerabilities 612