CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2025-1739
HIGH
Trivision Camera NC227WF v5.8.0 - Auth Bypass
CVSS 7.1
CVE-2025-1717
HIGH
Login Me Now < 1.7.2 - Unauthenticated Authentication Bypass via Arbitrary Transient Name
CVSS 8.1
CVE-2025-26966
CRITICAL
Aldo Latino PrivateContent <8.11.5 - Auth Bypass
CVSS 9.8
CVE-2025-26700
MEDIUM
RoboForm Password Manager <9.7.4 - Auth Bypass
CVSS 5.2
CVE-2025-1283
CRITICAL
Dingtian DT-R0 Series - Auth Bypass
CVSS 9.8
CVE-2025-24472
HIGH
KEV
FortiProxy 7.0.0-7.0.19 and FortiOS 7.0.0-7.0.16 - Unauthenticated Authentication Bypass via CSF Proxy Requests
CVSS 8.1
CVE-2025-0181
CRITICAL
WP Foodbakery <4.7 - Privilege Escalation
CVSS 9.8
CVE-2025-0316
CRITICAL
WP Directorybox Manager <2.5 - Auth Bypass
CVSS 9.8
CVE-2025-1061
CRITICAL
Nextend Social Login Pro <3.1.16 - Auth Bypass
CVSS 9.8
CVE-2025-0674
CRITICAL
Elber Signum DVB-S/S2 IRD < 1.999 - Authentication Bypass via Password Management Endpoint
CVSS 9.8
CVE-2025-23217
HIGH
mitmproxy < 11.1.2 - Server-Side Request Forgery via Proxy to Internal API
CVE-2025-0364
CRITICAL
BigAntSoft BigAnt Server <5.6.06 - RCE
CVSS 9.8
CVE-2025-24456
MEDIUM
JetBrains Hub < 2024.3.55417 - Privilege Escalation via LDAP Authentication Mapping
CVSS 6.7
CVE-2024-44286
HIGH
macOS < 15.1 - Authentication Bypass via Keyboard Events on Locked Device
CVSS 7.5
CVE-2024-26009
HIGH
Fortinet Fortiswitchmanager < 7.0.4 - Authentication Bypass
CVSS 8.1
CVE-2024-33939
MEDIUM
Masteriyo - LMS <1.7.3 - Auth Bypass
CVSS 5.3
CVE-2024-12225
CRITICAL
Quarkus < 3.15.3.1 - Authentication Bypass via Default WebAuthn REST Endpoints
CVSS 9.1
CVE-2024-42178
LOW
HCL MyXalytics - Unauthenticated Information Disclosure via Unrestricted URL Access
CVSS 2.5
CVE-2024-13553
CRITICAL
SMS Alert Order Notifications < 3.7.9 - Unauthenticated Privilege Escalation via Host Header Spoofing
CVSS 9.8
CVE-2024-56325
CRITICAL
Apache Pinot < 1.3.0 - Authentication Bypass via Path Manipulation
CVSS 9.8
CVE-2024-13442
CRITICAL
Service Finder Bookings <5.0 - Privilege Escalation
CVSS 9.8
CVE-2024-13772
MEDIUM
Civi WordPress Theme <= 2.1.6.1 - Unauthenticated Authentication Bypass via Social Login
CVSS 5.6
CVE-2024-13771
CRITICAL
Civi WordPress Theme <= 2.1.4 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2024-11286
CRITICAL
Chimpgroup Jobcareer < 7.1 - Authentication Bypass
CVSS 9.8
CVE-2024-13446
CRITICAL
Workreap plugin <3.2.5 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities
612