CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2022-23767 HIGH
SecureGate - Unauthenticated SQL Injection and Path Traversal via Login and File Transfer
CVSS 8.8
CVE-2022-36093 HIGH
XWiki Platform Web Templates <14.2 & <13.10.4 - Auth Bypass
CVSS 8.5
CVE-2022-34372 CRITICAL
Dell PowerProtect Cyber Recovery < 19.11.0.2 - Unauthenticated Authentication Bypass via Docker Registry API
CVSS 9.8
CVE-2022-2031 HIGH
Samba < 4.14.14 - Authentication Bypass via Shared KDC and kpasswd Keys
CVSS 8.8
CVE-2022-35869 CRITICAL
Inductive Automation Ignition 8.1.15 - Auth Bypass
CVSS 9.8
CVE-2022-30623 MEDIUM
CHCNAV P5E GNSS Firmware - Improper Authentication via Cookie Status Bypass
CVSS 5.9
CVE-2022-23725 HIGH
PingID Integration for Windows Login < 2.8 - Insufficiently Protected Credentials via Registry Permissions
CVSS 7.7
CVE-2022-23720 HIGH
PingID Windows Login <2.8 - Privilege Escalation
CVSS 7.5
CVE-2022-23719 HIGH
PingID Windows Login < 2.8 - Unauthenticated Spoofing via Local Java Service
CVSS 7.2
CVE-2022-31022 MEDIUM
Bleve < 2.5.0 - Unauthenticated Arbitrary Directory Creation and Deletion via HTTP Handlers
CVSS 6.2
CVE-2022-26865 MEDIUM
Dell Support Assist OS Recovery <5.5.2 - Auth Bypass
CVSS 6.8
CVE-2022-1681 HIGH
wiki.js < 2.5.281 - Authentication Bypass via Alternate Path
CVSS 7.2
CVE-2022-23724 MEDIUM
PingIdentity PingID Integration for Windows Login <= 2.4.2 - Authentication Bypass
CVSS 6.4
CVE-2022-23723 HIGH
PingFederate PingOne MFA Integration Kit - MFA Bypass via Adapter HTML Templates
CVSS 7.7
CVE-2022-23722 MEDIUM
PingFederate - Improper Authentication via Password Reset Mechanism
CVSS 6.5
CVE-2022-0992 CRITICAL
SiteGround Security Optimizer <= 1.2.5 - Unauthenticated Authentication Bypass via 2FA Setup
CVSS 9.8
CVE-2022-22189 HIGH
Juniper Networks CSO <6.0.0 Patch v3 - Privilege Escalation
CVSS 7.3
CVE-2022-1067 MEDIUM
Lifepoint Patient Portal < lpi_3.5.12.p30 - Unauthenticated Lab Report PDF Generation
CVSS 6.5
CVE-2022-24813 MEDIUM
CreateWiki < 2022-04-02 - Unauthenticated Anonymous Comment Posting via Special:RequestWikiQueue
CVSS 5.3
CVE-2022-24047 CRITICAL
BMC Track-It! 20.21.01.102 - Auth Bypass
CVSS 9.8
CVE-2021-4353 MEDIUM
WooCommerce Dynamic Pricing & Discounts <2.4.1 - Info Disclosure
CVSS 5.3
CVE-2021-4373 HIGH
Better Search <= 2.5.2 - Cross-Site Request Forgery via Settings Import
CVSS 8.8
CVE-2021-41995 HIGH
PingID Integration for Mac Login < 1.1 - MFA Bypass via RSA Misconfiguration
CVSS 7.7
CVE-2021-35530 MEDIUM
Hitachi Energy TXpert Hub CoreTec <2.2 - Privilege Escalation
CVSS 6.0
CVE-2021-26634 CRITICAL
maxb maxboard < 1.9.6 - Unrestricted File Upload and SQL Injection
CVSS 9.8
Details
Vulnerabilities 612