CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2023-2986 CRITICAL
Abandoned Cart Lite for WooCommerce <= 5.14.2 - Unauthenticated Authentication Bypass via Insufficient Encryption
CVSS 9.8
CVE-2023-2546 HIGH
WP User Switch <= 1.0.2 - Authenticated Authentication Bypass via wpus_who_switch Cookie
CVSS 8.8
CVE-2023-2781 HIGH
User Email Verification for WooCommerce <= 3.5.0 - Unauthenticated Authentication Bypass via Email Verification Token
CVSS 8.1
CVE-2023-2734 CRITICAL
MStore API < 3.9.1 - Unauthenticated Authentication Bypass via Cart Sync REST API
CVSS 9.8
CVE-2023-2733 CRITICAL
MStore API < 3.9.0 - Unauthenticated Authentication Bypass via Coupon Redemption REST API
CVSS 9.8
CVE-2023-2732 CRITICAL
MStore API < 3.9.2 - Unauthenticated Authentication Bypass via Listing REST API
CVSS 9.8
CVE-2023-2704 CRITICAL
BP Social Connect <= 1.5 - Unauthenticated Authentication Bypass via Facebook Login
CVSS 9.8
CVE-2023-20003 MEDIUM
Cisco Business Wireless APs - Auth Bypass
CVSS 4.7
CVE-2023-2499 CRITICAL
RegistrationMagic < 5.2.1.0 - Unauthenticated Authentication Bypass via Google Social Login
CVSS 9.8
CVE-2023-31152 MEDIUM
Schweitzer Engineering Laboratories SEL RTAC - Auth Bypass
CVSS 4.0
CVE-2023-21098 HIGH
Android - Local Privilege Escalation
CVSS 7.8
CVE-2023-2027 CRITICAL
ZM Ajax Login & Register < 2.0.2 - Unauthenticated Authentication Bypass via Facebook Login
CVSS 9.8
CVE-2023-23503 MEDIUM
iPadOS < 15.7.3 - Privacy Preferences Bypass via Logic Issue
CVSS 5.5
CVE-2023-20018 HIGH
Cisco IP Phone <7800-8800 - Auth Bypass
CVSS 8.6
CVE-2023-22495 CRITICAL
maif izanami < 1.11.0 - Authentication Bypass via Hardcoded JWT Secret
CVSS 9.8
CVE-2022-25369 CRITICAL
Dynamicweb < 9.12.8 - Unauthenticated Administrator User Creation and Remote Code Execution
CVSS 9.8
CVE-2022-36249 MEDIUM
Shop Beat Media Player <3.2.57 - Auth Bypass
CVSS 5.4
CVE-2022-40725 HIGH
PingID Desktop < 1.7.4 - Authentication Bypass via PIN Attempt Limit
CVSS 7.3
CVE-2022-42277 HIGH
NVIDIA DGX Station A100 Firmware < 10.16 - Authenticated Arbitrary Flash Read/Write/Erase via SmiFlash
CVSS 7.5
CVE-2022-42276 HIGH
NVIDIA DGX A100 Firmware < 1.18 - Authenticated Arbitrary Flash Access via SmiFlash
CVSS 7.5
CVE-2022-42275 HIGH
NVIDIA BMC < 00.19.07 - Unauthenticated SPI Flash Write via IPMI Handler
CVSS 7.7
CVE-2022-3614 MEDIUM
Octopus Server 3.5-2022.3.10750 - Unauthenticated Open Redirect via AD Sign-In
CVSS 6.1
CVE-2022-47578 HIGH
Zoho ManageEngine Device Control Plus 10.1.2228.15 - Privilege Esca...
CVSS 7.1
CVE-2022-27510 CRITICAL
Citrix Gateway 12.1-<12.1-65.21 - Unauthenticated Improper Authentication
CVSS 9.8
CVE-2022-26870 HIGH
Dell PowerStore <2.1.0.x - Auth Bypass
CVSS 7.0
Details
Vulnerabilities 612