CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2025-1739 HIGH
Trivision Camera NC227WF v5.8.0 - Auth Bypass
CVSS 7.1
CVE-2025-1717 HIGH
Login Me Now < 1.7.2 - Unauthenticated Authentication Bypass via Arbitrary Transient Name
CVSS 8.1
CVE-2025-26966 CRITICAL
Aldo Latino PrivateContent <8.11.5 - Auth Bypass
CVSS 9.8
CVE-2025-26700 MEDIUM
RoboForm Password Manager <9.7.4 - Auth Bypass
CVSS 5.2
CVE-2025-1283 CRITICAL
Dingtian DT-R0 Series - Auth Bypass
CVSS 9.8
CVE-2025-24472 HIGH KEV
FortiProxy 7.0.0-7.0.19 and FortiOS 7.0.0-7.0.16 - Unauthenticated Authentication Bypass via CSF Proxy Requests
CVSS 8.1
CVE-2025-0181 CRITICAL
WP Foodbakery <4.7 - Privilege Escalation
CVSS 9.8
CVE-2025-0316 CRITICAL
WP Directorybox Manager <2.5 - Auth Bypass
CVSS 9.8
CVE-2025-1061 CRITICAL
Nextend Social Login Pro <3.1.16 - Auth Bypass
CVSS 9.8
CVE-2025-0674 CRITICAL
Elber Signum DVB-S/S2 IRD < 1.999 - Authentication Bypass via Password Management Endpoint
CVSS 9.8
CVE-2025-23217 HIGH
mitmproxy < 11.1.2 - Server-Side Request Forgery via Proxy to Internal API
CVE-2025-0364 CRITICAL
BigAntSoft BigAnt Server <5.6.06 - RCE
CVSS 9.8
CVE-2025-24456 MEDIUM
JetBrains Hub < 2024.3.55417 - Privilege Escalation via LDAP Authentication Mapping
CVSS 6.7
CVE-2024-44286 HIGH
macOS < 15.1 - Authentication Bypass via Keyboard Events on Locked Device
CVSS 7.5
CVE-2024-26009 HIGH
Fortinet Fortiswitchmanager < 7.0.4 - Authentication Bypass
CVSS 8.1
CVE-2024-33939 MEDIUM
Masteriyo - LMS <1.7.3 - Auth Bypass
CVSS 5.3
CVE-2024-12225 CRITICAL
Quarkus < 3.15.3.1 - Authentication Bypass via Default WebAuthn REST Endpoints
CVSS 9.1
CVE-2024-42178 LOW
HCL MyXalytics - Unauthenticated Information Disclosure via Unrestricted URL Access
CVSS 2.5
CVE-2024-13553 CRITICAL
SMS Alert Order Notifications < 3.7.9 - Unauthenticated Privilege Escalation via Host Header Spoofing
CVSS 9.8
CVE-2024-56325 CRITICAL
Apache Pinot < 1.3.0 - Authentication Bypass via Path Manipulation
CVSS 9.8
CVE-2024-13442 CRITICAL
Service Finder Bookings <5.0 - Privilege Escalation
CVSS 9.8
CVE-2024-13772 MEDIUM
Civi WordPress Theme <= 2.1.6.1 - Unauthenticated Authentication Bypass via Social Login
CVSS 5.6
CVE-2024-13771 CRITICAL
Civi WordPress Theme <= 2.1.4 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2024-11286 CRITICAL
Chimpgroup Jobcareer < 7.1 - Authentication Bypass
CVSS 9.8
CVE-2024-13446 CRITICAL
Workreap plugin <3.2.5 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities 612