CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2023-2986
CRITICAL
Abandoned Cart Lite for WooCommerce <= 5.14.2 - Unauthenticated Authentication Bypass via Insufficient Encryption
CVSS 9.8
CVE-2023-2546
HIGH
WP User Switch <= 1.0.2 - Authenticated Authentication Bypass via wpus_who_switch Cookie
CVSS 8.8
CVE-2023-2781
HIGH
User Email Verification for WooCommerce <= 3.5.0 - Unauthenticated Authentication Bypass via Email Verification Token
CVSS 8.1
CVE-2023-2734
CRITICAL
MStore API < 3.9.1 - Unauthenticated Authentication Bypass via Cart Sync REST API
CVSS 9.8
CVE-2023-2733
CRITICAL
MStore API < 3.9.0 - Unauthenticated Authentication Bypass via Coupon Redemption REST API
CVSS 9.8
CVE-2023-2732
CRITICAL
MStore API < 3.9.2 - Unauthenticated Authentication Bypass via Listing REST API
CVSS 9.8
CVE-2023-2704
CRITICAL
BP Social Connect <= 1.5 - Unauthenticated Authentication Bypass via Facebook Login
CVSS 9.8
CVE-2023-20003
MEDIUM
Cisco Business Wireless APs - Auth Bypass
CVSS 4.7
CVE-2023-2499
CRITICAL
RegistrationMagic < 5.2.1.0 - Unauthenticated Authentication Bypass via Google Social Login
CVSS 9.8
CVE-2023-31152
MEDIUM
Schweitzer Engineering Laboratories SEL RTAC - Auth Bypass
CVSS 4.0
CVE-2023-21098
HIGH
Android - Local Privilege Escalation
CVSS 7.8
CVE-2023-2027
CRITICAL
ZM Ajax Login & Register < 2.0.2 - Unauthenticated Authentication Bypass via Facebook Login
CVSS 9.8
CVE-2023-23503
MEDIUM
iPadOS < 15.7.3 - Privacy Preferences Bypass via Logic Issue
CVSS 5.5
CVE-2023-20018
HIGH
Cisco IP Phone <7800-8800 - Auth Bypass
CVSS 8.6
CVE-2023-22495
CRITICAL
maif izanami < 1.11.0 - Authentication Bypass via Hardcoded JWT Secret
CVSS 9.8
CVE-2022-25369
CRITICAL
Dynamicweb < 9.12.8 - Unauthenticated Administrator User Creation and Remote Code Execution
CVSS 9.8
CVE-2022-36249
MEDIUM
Shop Beat Media Player <3.2.57 - Auth Bypass
CVSS 5.4
CVE-2022-40725
HIGH
PingID Desktop < 1.7.4 - Authentication Bypass via PIN Attempt Limit
CVSS 7.3
CVE-2022-42277
HIGH
NVIDIA DGX Station A100 Firmware < 10.16 - Authenticated Arbitrary Flash Read/Write/Erase via SmiFlash
CVSS 7.5
CVE-2022-42276
HIGH
NVIDIA DGX A100 Firmware < 1.18 - Authenticated Arbitrary Flash Access via SmiFlash
CVSS 7.5
CVE-2022-42275
HIGH
NVIDIA BMC < 00.19.07 - Unauthenticated SPI Flash Write via IPMI Handler
CVSS 7.7
CVE-2022-3614
MEDIUM
Octopus Server 3.5-2022.3.10750 - Unauthenticated Open Redirect via AD Sign-In
CVSS 6.1
CVE-2022-47578
HIGH
Zoho ManageEngine Device Control Plus 10.1.2228.15 - Privilege Esca...
CVSS 7.1
CVE-2022-27510
CRITICAL
Citrix Gateway 12.1-<12.1-65.21 - Unauthenticated Improper Authentication
CVSS 9.8
CVE-2022-26870
HIGH
Dell PowerStore <2.1.0.x - Auth Bypass
CVSS 7.0
Details
Vulnerabilities
612