CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2024-47406 CRITICAL
Sharp and Toshiba Tec MFPs - Auth Bypass
CVSS 9.1
CVE-2024-9488 CRITICAL
Comments - wpDiscuz <= 7.6.24 - Unauthenticated Authentication Bypass via Social Login Token
CVSS 9.8
CVE-2024-49675 HIGH
iBryl Switch User <1.0.1 - Auth Bypass
CVSS 8.8
CVE-2024-10002 HIGH
Rover IDX <3.0.0.2906 - Auth Bypass
CVSS 8.8
CVE-2024-49604 CRITICAL
Najeeb Ahmad Simple User Registration <5.5 - Auth Bypass
CVSS 9.8
CVE-2024-49328 CRITICAL
WP REST API FNS <= 1.0.0 - Authentication Bypass
CVSS 9.8
CVE-2024-9861 HIGH
Miniorange OTP Verification with Firebase <= 3.6.0 - Unauthenticated Authentication Bypass via OTP Login Token
CVSS 8.1
CVE-2024-9893 CRITICAL
Nextend Social Login Pro <3.1.14 - Auth Bypass
CVSS 9.8
CVE-2024-49247 CRITICAL
BuddyPress Better Registration <= 1.6 - Authentication Bypass
CVSS 9.8
CVE-2024-9105 CRITICAL
UltimateAI plugin <2.8.3 - Auth Bypass
CVSS 9.8
CVE-2024-9822 CRITICAL
Pedalo Connector <= 2.0.5 - Unauthenticated Authentication Bypass via login_admin_user Function
CVSS 9.8
CVE-2024-9522 HIGH
WP Users Masquerade <= 2.0.0 - Authenticated Authentication Bypass via ajax_masq_login Function
CVSS 8.8
CVE-2024-47010 HIGH
Ivanti Avalanche <6.4.5 - Path Traversal
CVSS 7.3
CVE-2024-47009 HIGH
Ivanti Avalanche <6.4.5 - Path Traversal
CVSS 7.3
CVE-2024-8943 CRITICAL
LatePoint Plugin <= 5.0.12 - Unauthenticated Authentication Bypass via User ID
CVSS 9.8
CVE-2024-46887 MEDIUM
SIMATIC Drive Controller and ET 200SP CPU < V3.1.4 - Unauthenticated Information Disclosure via RuntimeInfoData Endpoint
CVSS 5.3
CVE-2024-9289 CRITICAL
WordPress WooCommerce Affiliate Program <= 8.4.1 - Authentication Bypass
CVSS 9.8
CVE-2024-9106 CRITICAL
Wechat Social login plugin <1.3.0 - Auth Bypass
CVSS 9.8
CVE-2024-7781 HIGH
Jupiter X Core < 4.7.8 - Unauthenticated Authentication Bypass via Social Login Widget
CVSS 8.1
CVE-2024-43692 CRITICAL
ProGauge MAGLINK LX CONSOLE - Privilege Escalation
CVSS 9.8
CVE-2024-8277 CRITICAL
WooCommerce Photo Reviews Premium <1.3.13.2 - Auth Bypass
CVSS 9.8
CVE-2024-8012 HIGH
Ivanti Workspace Control <2025.2 - Privilege Escalation
CVSS 7.8
CVE-2024-41173 HIGH
Beckhoff IPC-Diagnostics Package < 2.0.0.1 and TwinCAT/BSD < 14.1.2.0 - Local Authentication Bypass
CVSS 7.8
CVE-2024-7125 HIGH
Hitachi Ops Center Common Services 10.9.3-00-11.0.2-01 - Authentication Bypass
CVSS 7.8
CVE-2024-35151 MEDIUM
IBM OpenPages with Watson 8.3 and 9.0 - Authenticated Sensitive Information Exposure via API Authorization Bypass
CVSS 6.5
Details
Vulnerabilities 612