CWE-288
Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
612 vulnerabilities with CWE-288
CVE-2022-23767
HIGH
SecureGate - Unauthenticated SQL Injection and Path Traversal via Login and File Transfer
CVSS 8.8
CVE-2022-36093
HIGH
XWiki Platform Web Templates <14.2 & <13.10.4 - Auth Bypass
CVSS 8.5
CVE-2022-34372
CRITICAL
Dell PowerProtect Cyber Recovery < 19.11.0.2 - Unauthenticated Authentication Bypass via Docker Registry API
CVSS 9.8
CVE-2022-2031
HIGH
Samba < 4.14.14 - Authentication Bypass via Shared KDC and kpasswd Keys
CVSS 8.8
CVE-2022-35869
CRITICAL
Inductive Automation Ignition 8.1.15 - Auth Bypass
CVSS 9.8
CVE-2022-30623
MEDIUM
CHCNAV P5E GNSS Firmware - Improper Authentication via Cookie Status Bypass
CVSS 5.9
CVE-2022-23725
HIGH
PingID Integration for Windows Login < 2.8 - Insufficiently Protected Credentials via Registry Permissions
CVSS 7.7
CVE-2022-23720
HIGH
PingID Windows Login <2.8 - Privilege Escalation
CVSS 7.5
CVE-2022-23719
HIGH
PingID Windows Login < 2.8 - Unauthenticated Spoofing via Local Java Service
CVSS 7.2
CVE-2022-31022
MEDIUM
Bleve < 2.5.0 - Unauthenticated Arbitrary Directory Creation and Deletion via HTTP Handlers
CVSS 6.2
CVE-2022-26865
MEDIUM
Dell Support Assist OS Recovery <5.5.2 - Auth Bypass
CVSS 6.8
CVE-2022-1681
HIGH
wiki.js < 2.5.281 - Authentication Bypass via Alternate Path
CVSS 7.2
CVE-2022-23724
MEDIUM
PingIdentity PingID Integration for Windows Login <= 2.4.2 - Authentication Bypass
CVSS 6.4
CVE-2022-23723
HIGH
PingFederate PingOne MFA Integration Kit - MFA Bypass via Adapter HTML Templates
CVSS 7.7
CVE-2022-23722
MEDIUM
PingFederate - Improper Authentication via Password Reset Mechanism
CVSS 6.5
CVE-2022-0992
CRITICAL
SiteGround Security Optimizer <= 1.2.5 - Unauthenticated Authentication Bypass via 2FA Setup
CVSS 9.8
CVE-2022-22189
HIGH
Juniper Networks CSO <6.0.0 Patch v3 - Privilege Escalation
CVSS 7.3
CVE-2022-1067
MEDIUM
Lifepoint Patient Portal < lpi_3.5.12.p30 - Unauthenticated Lab Report PDF Generation
CVSS 6.5
CVE-2022-24813
MEDIUM
CreateWiki < 2022-04-02 - Unauthenticated Anonymous Comment Posting via Special:RequestWikiQueue
CVSS 5.3
CVE-2022-24047
CRITICAL
BMC Track-It! 20.21.01.102 - Auth Bypass
CVSS 9.8
CVE-2021-4353
MEDIUM
WooCommerce Dynamic Pricing & Discounts <2.4.1 - Info Disclosure
CVSS 5.3
CVE-2021-4373
HIGH
Better Search <= 2.5.2 - Cross-Site Request Forgery via Settings Import
CVSS 8.8
CVE-2021-41995
HIGH
PingID Integration for Mac Login < 1.1 - MFA Bypass via RSA Misconfiguration
CVSS 7.7
CVE-2021-35530
MEDIUM
Hitachi Energy TXpert Hub CoreTec <2.2 - Privilege Escalation
CVSS 6.0
CVE-2021-26634
CRITICAL
maxb maxboard < 1.9.6 - Unrestricted File Upload and SQL Injection
CVSS 9.8
Details
Vulnerabilities
612