CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2024-35214 HIGH
CylanceOPTICS <3.3 - Privilege Escalation
CVE-2024-7628 HIGH
MStore API < 4.15.2 - Unauthenticated Authentication Bypass via Loose Comparison in verify_id_token
CVSS 8.1
CVE-2024-35124 HIGH
IBM OpenBMC fw1020.00-fw1020.60 - Unauthenticated Administrative Access via Default Password
CVSS 7.5
CVE-2024-7503 CRITICAL
WooCommerce - Social Login <= 2.7.5 - Unauthenticated Authentication Bypass via Loose Activation Code Comparison
CVSS 9.8
CVE-2024-6684 CRITICAL
GST Electronics inohom Nova Panel N7 <1.9.9.6 - Auth Bypass
CVE-2024-7350 CRITICAL
BookingPress 1.1.6-1.1.7 - Unauthenticated Authentication Bypass via Auto-Login
CVSS 9.8
CVE-2024-7314 CRITICAL
anji-plus report < 1.4.1 - Unauthenticated Authentication Bypass via Swagger UI Path
CVSS 9.8
CVE-2024-7007 CRITICAL
Positron TRA7005 Firmware v1.20 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2024-7027 HIGH
WooCommerce - PDF Vouchers <4.9.3 - Auth Bypass
CVSS 7.3
CVE-2024-38437 CRITICAL
D-Link DSL-225 Firmware - Authentication Bypass via Alternate Path
CVSS 9.8
CVE-2024-6635 HIGH
WooCommerce - Social Login <2.7.3 - Auth Bypass
CVSS 7.3
CVE-2024-5620 MEDIUM
PruvaSoft Informatics Apinizer Management Console <2024.05.1 - Auth...
CVSS 6.5
CVE-2024-6328 CRITICAL
MStore API < 4.14.7 - Unauthenticated Authentication Bypass via Phone Parameter
CVSS 9.8
CVE-2024-6397 CRITICAL
InstaWP Connect <0.1.0.44 - Auth Bypass
CVSS 9.8
CVE-2024-39309 CRITICAL
Parse Server < 6.5.7 and 7.0.0-7.1.0 - SQL Injection via PostgreSQL Configuration
CVSS 9.8
CVE-2024-5322 CRITICAL
n-able n-central < 2024.3 - Authentication Bypass via Entra SSO Session Rebinding
CVSS 9.1
CVE-2024-28200 CRITICAL
N-able N-central < 2024.2 - Authentication Bypass Detection
CVSS 9.1
CVE-2024-2973 CRITICAL
Juniper Networks Session Smart Router - Auth Bypass
CVSS 10.0
CVE-2024-31916 HIGH
IBM OpenBMC FW1050.00-FW1050.10 - Info Disclosure
CVSS 7.5
CVE-2024-5432 CRITICAL
Lifeline Donation < 1.2.6 - Unauthenticated Authentication Bypass via Checkout
CVSS 9.8
CVE-2024-37893 MEDIUM
Firefly III < 6.1.17 - MFA Bypass via OAuth Flow
CVSS 5.9
CVE-2024-3496 HIGH
Toshiba Tec e-Studio multi-function peripheral (MFP) - Authentication Bypass via Web Login
CVSS 8.8
CVE-2024-38279 MEDIUM
Motorola Vigilant Fixed LPR COMS Box Firmware <= 3.1.171.9 - Authentication Bypass
CVSS 4.6
CVE-2024-2013 CRITICAL
HitachiEnergy FOXMAN-UN/UNEM - Unauthenticated Authentication Bypass in API Gateway
CVSS 10.0
CVE-2024-2012 CRITICAL
HitachiEnergy FOXMAN-UN/UNEM - Authentication Bypass and Remote Code Execution
CVSS 9.1
Details
Vulnerabilities 612