CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2024-4552 CRITICAL
Social Login Lite For WooCommerce <1.6.0 - Auth Bypass
CVSS 9.8
CVE-2024-36042 CRITICAL
Silverpeas < 6.3.5 - Authentication Bypass via Omitted Password Field
CVSS 9.8
CVE-2024-36470 HIGH
JetBrains TeamCity <2022.04.7,2022.10.6,2023.05.6,2023.11.5 - Auth ...
CVSS 8.1
CVE-2024-5204 HIGH
Swiss Toolkit For WP <1.0.7 - Auth Bypass
CVSS 8.8
CVE-2024-5150 CRITICAL
WordPress Login with phone number <1.7.26 - Auth Bypass
CVSS 9.8
CVE-2024-4544 CRITICAL
The Pie Register - Social Sites Login (Add on) <1.7.7 - Auth Bypass
CVSS 9.8
CVE-2024-29853 HIGH
Veeam Agent for Microsoft Windows - Privilege Escalation
CVSS 7.8
CVE-2024-4393 CRITICAL
Social Connect <= 1.2 - Unauthenticated Authentication Bypass via OpenID Verification
CVSS 9.8
CVE-2024-4186 CRITICAL
WordPress Build App Online <3.0.5 - Auth Bypass
CVSS 9.8
CVE-2024-34524 CRITICAL
XLANG OpenAgents <fe73ac4 - Info Disclosure
CVSS 9.1
CVE-2024-31463 MEDIUM
Ironic-image <24.1.1 - Missing Authentication on Ironic API in Reverse Proxy Mode
CVSS 4.7
CVE-2024-1646 HIGH
lollms-webui < 9.3 - Unauthenticated Authentication Bypass via Host Parameter Check
CVSS 8.2
CVE-2024-31814 HIGH
TOTOLINK EX200 V4.0.3c.7646_B20201211 - Auth Bypass
CVSS 8.8
CVE-2024-26566 HIGH
Cute Http File Server <3.1 - Privilege Escalation
CVSS 8.2
CVE-2024-2056 CRITICAL
Artica Proxy - Unauthenticated Arbitrary File Read via Exposed Tailon Service
CVSS 9.8
CVE-2024-2055 CRITICAL
Artica Proxy - Privilege Escalation
CVSS 9.8
CVE-2024-27198 CRITICAL KEV
TeamCity < 2023.11.4 - Authentication Bypass
CVSS 9.8
CVE-2024-1525 MEDIUM
GitLab CE/EE <16.7.6-16.8.3-16.9.1 - Auth Bypass
CVSS 5.3
CVE-2024-1709 CRITICAL KEV
ConnectWise ScreenConnect < 23.9.8 - Authentication Bypass
CVSS 10.0
CVE-2024-21491 MEDIUM
svix-webhooks < 1.17.0 - Authentication Bypass via Signature Length Mismatch
CVSS 5.9
CVE-2024-23917 CRITICAL
JetBrains TeamCity > 2023.11.3 - Authentication Bypass
CVSS 9.8
CVE-2023-49564 HIGH
Nokia CBIS/NCS - Unauthenticated Authentication Bypass via Crafted HTTP Header
CVSS 8.8
CVE-2023-37057 CRITICAL
Jlink AX1800 1.0 - Remote Code Execution via Authentication Mechanism
CVSS 9.8
CVE-2023-50915 MEDIUM
GOG Galaxy (Beta) <2.0.71.2 - Privilege Escalation
CVSS 6.5
CVE-2023-50272 HIGH
HPE Integrated Lights-Out 5 2.63-3.00 and iLO 6 1.05-1.55 - Authentication Bypass
CVSS 7.5
Details
Vulnerabilities 612