CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2024-9658
HIGH
School Management System for Wordpress < 93.0.0 - Authenticated Privilege Escalation via User Detail Update Functions
CVSS 8.8
CVE-2024-13182
CRITICAL
WP Directorybox Manager <2.5 - Auth Bypass
CVSS 9.8
CVE-2024-12857
CRITICAL
AdForest < 5.1.8 - Unauthenticated Authentication Bypass via OTP Login
CVSS 9.8
CVE-2024-13181
HIGH
Ivanti Avalanche <6.4.7 - Path Traversal
CVSS 7.3
CVE-2024-13179
HIGH
Ivanti Avalanche <6.4.7 - Path Traversal
CVSS 7.3
CVE-2024-55591
CRITICAL
KEV
FortiProxy 7.0.0-7.0.19 and 7.2.0-7.2.12 - Authentication Bypass via Node.js Websocket Module
CVSS 9.8
CVE-2024-12402
CRITICAL
Themes Coder - Privilege Escalation
CVSS 9.8
CVE-2024-56044
CRITICAL
VibeThemes WPLMS < 1.9.9 - Unauthenticated Authentication Bypass via Alternate Path
CVSS 9.8
CVE-2024-51464
MEDIUM
IBM i 7.3-7.5 - Authenticated Authentication Bypass via Navigator for i Interface
CVSS 4.3
CVE-2024-11349
CRITICAL
AdForest theme <5.1.6 - Auth Bypass
CVSS 9.8
CVE-2024-43234
CRITICAL
Woffice < 5.4.14 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2024-56013
HIGH
Wovax IDX <= 1.2.2 - Authentication Bypass
CVSS 8.8
CVE-2024-54336
HIGH
Projectopia <= 5.1.7 - Authentication Bypass via Alternate Path
CVSS 8.8
CVE-2024-54297
CRITICAL
www.vbsso.com vBSSO-lite - Auth Bypass
CVSS 9.8
CVE-2024-54296
CRITICAL
CoSchool LMS <= 1.4.3 - Authentication Bypass
CVSS 9.8
CVE-2024-54295
CRITICAL
InspireUI ListApp Mobile Manager <1.7.7 - Auth Bypass
CVSS 9.8
CVE-2024-54294
CRITICAL
appgenixinfotech Firebase OTP Auth <1.0.1 - Auth Bypass
CVSS 9.8
CVE-2024-11639
CRITICAL
Ivanti Cloud Services Appliance < 5.0.3 - Unauthenticated Authentication Bypass in Admin Web Console
CVSS 10.0
CVE-2024-52586
MEDIUM
elabftw 4.6.0-5.1.8 - Multifactor Authentication Bypass via Local Authentication
CVSS 5.4
CVE-2024-11178
HIGH
Login With OTP plugin <1.4.2 - Auth Bypass
CVSS 8.1
CVE-2024-25036
MEDIUM
IBM Cognos Controller <11.0.1 - Auth Bypass
CVSS 4.3
CVE-2024-10490
HIGH
B&R mapp Services <6.0 - Auth Bypass
CVE-2024-11981
HIGH
Billion Electric Router - Auth Bypass
CVSS 7.5
CVE-2024-52475
CRITICAL
Wawp < 3.0.18 - Authentication Bypass
CVSS 9.8
CVE-2024-11925
CRITICAL
JobSearch WP Job Board <2.6.7 - Privilege Escalation
CVSS 9.8
Details
Vulnerabilities
612