CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2023-6718
CRITICAL
Repox - Unauthenticated User Creation and Modification via Crafted POST Request
CVSS 9.4
CVE-2023-2437
CRITICAL
UserPro < 5.1.1 - Unauthenticated Authentication Bypass via Facebook Login
CVSS 9.8
CVE-2023-42770
CRITICAL
Redlioncontrols St-ipm-6350 Firmware - Missing Authentication
CVSS 10.0
CVE-2023-3277
CRITICAL
MStore API < 4.10.7 - Unauthenticated Account Access and Privilege Escalation via Apple Login Feature
CVSS 9.8
CVE-2023-41351
CRITICAL
Chunghwa Telecom NOKIA G-040W-Q - Auth Bypass
CVSS 9.8
CVE-2023-20247
MEDIUM
Cisco Adaptive Security Appliance Software - Authentication Bypass via Remote Access SSL VPN
CVSS 5.0
CVE-2023-46747
CRITICAL
KEV
F5 BIG-IP 13.1.0-13.1.4 - Unauthenticated Remote Command Execution via Configuration Utility Bypass
CVSS 9.8
CVE-2023-39930
HIGH
PingID Radius PCV 3.0.0-3.0.3 - Unauthenticated First-Factor Authentication Bypass via Malicious RADIUS Client Request
CVSS 7.5
CVE-2023-39231
HIGH
PingFederate PingOne MFA Integration Kit - Missing Authentication for MFA Device Pairing
CVSS 7.3
CVE-2023-43045
MEDIUM
IBM Sterling Partner Engagement Manager <6.2.2 - Privilege Escalation
CVSS 5.9
CVE-2023-46319
HIGH
WALLIX Bastion <9.0.9, <10.0.5 - Info Disclosure
CVSS 7.5
CVE-2023-4957
MEDIUM
Zebra ZT410 Firmware - Authentication Bypass via setvarsResults.cgi POST Request
CVSS 5.4
CVE-2023-42771
HIGH
FurunoSystems ACERA 1310 and 1320 Firmware < 01.26 - Unauthenticated Authentication Bypass
CVSS 8.8
CVE-2023-1260
HIGH
kube-apiserver - Authentication Bypass via Ephemeral Containers Subresource
CVSS 8.0
CVE-2023-42793
CRITICAL
KEV
JetBrains TeamCity < 2023.05.4 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2023-4702
CRITICAL
Yepas Digital Yepas < 1.0.1 - Authentication Bypass
CVSS 9.8
CVE-2023-41256
CRITICAL
Doverfuelingsolutions Maglink LX Web Console Configuration - Authentication Bypass
CVSS 9.1
CVE-2023-20269
MEDIUM
KEV
Cisco Adaptive Security Appliance Software - Authentication Bypass via Default Connection Profile
CVSS 5.0
CVE-2023-3162
CRITICAL
Stripe Payment Plugin for WooCommerce <3.7.7 - Auth Bypass
CVSS 9.8
CVE-2023-32002
CRITICAL
Node.js 16.0.0-16.20.1 - Policy Mechanism Bypass via Module._load()
CVSS 9.8
CVE-2023-3249
CRITICAL
Web3 - Crypto wallet Login & NFT token gating <= 2.6.0 - Authenticated Authentication Bypass via Hidden Form Data
CVSS 9.8
CVE-2023-2834
CRITICAL
BookIt WordPress <2.3.7 - Auth Bypass
CVSS 9.8
CVE-2023-30946
LOW
palantir/foundry_issues < 2.497.0 - Unauthenticated Metadata Exposure via Notification API
CVSS 3.5
CVE-2023-2982
CRITICAL
WordPress Social Login and Register <= 7.6.4 - Authentication Bypass via Insufficient Encryption
CVSS 9.8
CVE-2023-34335
HIGH
AMI MegaRAC SPX 12.0-12.7 - Unauthenticated SPI Flash Write via IPMI Handler
CVSS 7.7
Details
Vulnerabilities
612