CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2024-35214
HIGH
CylanceOPTICS <3.3 - Privilege Escalation
CVE-2024-7628
HIGH
MStore API < 4.15.2 - Unauthenticated Authentication Bypass via Loose Comparison in verify_id_token
CVSS 8.1
CVE-2024-35124
HIGH
IBM OpenBMC fw1020.00-fw1020.60 - Unauthenticated Administrative Access via Default Password
CVSS 7.5
CVE-2024-7503
CRITICAL
WooCommerce - Social Login <= 2.7.5 - Unauthenticated Authentication Bypass via Loose Activation Code Comparison
CVSS 9.8
CVE-2024-6684
CRITICAL
GST Electronics inohom Nova Panel N7 <1.9.9.6 - Auth Bypass
CVE-2024-7350
CRITICAL
BookingPress 1.1.6-1.1.7 - Unauthenticated Authentication Bypass via Auto-Login
CVSS 9.8
CVE-2024-7314
CRITICAL
anji-plus report < 1.4.1 - Unauthenticated Authentication Bypass via Swagger UI Path
CVSS 9.8
CVE-2024-7007
CRITICAL
Positron TRA7005 Firmware v1.20 - Unauthenticated Authentication Bypass
CVSS 9.8
CVE-2024-7027
HIGH
WooCommerce - PDF Vouchers <4.9.3 - Auth Bypass
CVSS 7.3
CVE-2024-38437
CRITICAL
D-Link DSL-225 Firmware - Authentication Bypass via Alternate Path
CVSS 9.8
CVE-2024-6635
HIGH
WooCommerce - Social Login <2.7.3 - Auth Bypass
CVSS 7.3
CVE-2024-5620
MEDIUM
PruvaSoft Informatics Apinizer Management Console <2024.05.1 - Auth...
CVSS 6.5
CVE-2024-6328
CRITICAL
MStore API < 4.14.7 - Unauthenticated Authentication Bypass via Phone Parameter
CVSS 9.8
CVE-2024-6397
CRITICAL
InstaWP Connect <0.1.0.44 - Auth Bypass
CVSS 9.8
CVE-2024-39309
CRITICAL
Parse Server < 6.5.7 and 7.0.0-7.1.0 - SQL Injection via PostgreSQL Configuration
CVSS 9.8
CVE-2024-5322
CRITICAL
n-able n-central < 2024.3 - Authentication Bypass via Entra SSO Session Rebinding
CVSS 9.1
CVE-2024-28200
CRITICAL
N-able N-central < 2024.2 - Authentication Bypass Detection
CVSS 9.1
CVE-2024-2973
CRITICAL
Juniper Networks Session Smart Router - Auth Bypass
CVSS 10.0
CVE-2024-31916
HIGH
IBM OpenBMC FW1050.00-FW1050.10 - Info Disclosure
CVSS 7.5
CVE-2024-5432
CRITICAL
Lifeline Donation < 1.2.6 - Unauthenticated Authentication Bypass via Checkout
CVSS 9.8
CVE-2024-37893
MEDIUM
Firefly III < 6.1.17 - MFA Bypass via OAuth Flow
CVSS 5.9
CVE-2024-3496
HIGH
Toshiba Tec e-Studio multi-function peripheral (MFP) - Authentication Bypass via Web Login
CVSS 8.8
CVE-2024-38279
MEDIUM
Motorola Vigilant Fixed LPR COMS Box Firmware <= 3.1.171.9 - Authentication Bypass
CVSS 4.6
CVE-2024-2013
CRITICAL
HitachiEnergy FOXMAN-UN/UNEM - Unauthenticated Authentication Bypass in API Gateway
CVSS 10.0
CVE-2024-2012
CRITICAL
HitachiEnergy FOXMAN-UN/UNEM - Authentication Bypass and Remote Code Execution
CVSS 9.1
Details
Vulnerabilities
612