CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
569 vulnerabilities with CWE-288
CVE-2024-27198
CRITICAL
KEV
TeamCity < 2023.11.4 - Authentication Bypass
CVSS 9.8
CVE-2024-1525
MEDIUM
GitLab CE/EE <16.7.6-16.8.3-16.9.1 - Auth Bypass
CVSS 5.3
CVE-2024-1709
CRITICAL
KEV
ConnectWise ScreenConnect < 23.9.8 - Authentication Bypass
CVSS 10.0
CVE-2024-21491
MEDIUM
svix-webhooks < 1.17.0 - Authentication Bypass via Signature Length Mismatch
CVSS 5.9
CVE-2024-23917
CRITICAL
JetBrains TeamCity > 2023.11.3 - Authentication Bypass
CVSS 9.8
CVE-2023-49564
HIGH
Nokia CBIS/NCS - Unauthenticated Authentication Bypass via Crafted HTTP Header
CVSS 8.8
CVE-2023-37057
CRITICAL
Jlink AX1800 1.0 - Remote Code Execution via Authentication Mechanism
CVSS 9.8
CVE-2023-50915
MEDIUM
GOG Galaxy (Beta) <2.0.71.2 - Privilege Escalation
CVSS 6.5
CVE-2023-50272
HIGH
HPE Integrated Lights-Out 5 2.63-3.00 and iLO 6 1.05-1.55 - Authentication Bypass
CVSS 7.5
CVE-2023-6718
CRITICAL
Repox - Unauthenticated User Creation and Modification via Crafted POST Request
CVSS 9.4
CVE-2023-2437
CRITICAL
UserPro < 5.1.1 - Unauthenticated Authentication Bypass via Facebook Login
CVSS 9.8
CVE-2023-42770
CRITICAL
Redlioncontrols St-ipm-6350 Firmware - Missing Authentication
CVSS 10.0
CVE-2023-3277
CRITICAL
MStore API < 4.10.7 - Unauthenticated Account Access and Privilege Escalation via Apple Login Feature
CVSS 9.8
CVE-2023-41351
CRITICAL
Chunghwa Telecom NOKIA G-040W-Q - Auth Bypass
CVSS 9.8
CVE-2023-20247
MEDIUM
Cisco Adaptive Security Appliance Software - Authentication Bypass via Remote Access SSL VPN
CVSS 5.0
CVE-2023-46747
CRITICAL
KEV
F5 BIG-IP 13.1.0-13.1.4 - Unauthenticated Remote Command Execution via Configuration Utility Bypass
CVSS 9.8
CVE-2023-39930
HIGH
PingID Radius PCV 3.0.0-3.0.3 - Unauthenticated First-Factor Authentication Bypass via Malicious RADIUS Client Request
CVSS 7.5
CVE-2023-39231
HIGH
PingFederate PingOne MFA Integration Kit - Missing Authentication for MFA Device Pairing
CVSS 7.3
CVE-2023-43045
MEDIUM
IBM Sterling Partner Engagement Manager <6.2.2 - Privilege Escalation
CVSS 5.9
CVE-2023-46319
HIGH
WALLIX Bastion <9.0.9, <10.0.5 - Info Disclosure
CVSS 7.5
CVE-2023-4957
MEDIUM
Zebra ZT410 Firmware - Authentication Bypass via setvarsResults.cgi POST Request
CVSS 5.4
CVE-2023-42771
HIGH
FurunoSystems ACERA 1310 and 1320 Firmware < 01.26 - Unauthenticated Authentication Bypass
CVSS 8.8
CVE-2023-1260
HIGH
kube-apiserver - Authentication Bypass via Ephemeral Containers Subresource
CVSS 8.0
CVE-2023-42793
CRITICAL
KEV
JetBrains TeamCity < 2023.05.4 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2023-4702
CRITICAL
Yepas Digital Yepas < 1.0.1 - Authentication Bypass
CVSS 9.8
Details
Vulnerabilities
569