CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

522 vulnerabilities with CWE-288
CVE-2025-7444 CRITICAL
LoginPress Pro <5.0.1 - Auth Bypass
CVSS 9.8
CVE-2025-1313 HIGH
Nokri - Job Board WordPress Theme <1.6.3 - Privilege Escalation
CVSS 8.8
CVE-2025-30026 CRITICAL
AXIS Camera Station Server - Auth Bypass
CVSS 9.8
CVE-2025-24332 HIGH
Nokia Single RAN AirScale - Privilege Escalation
CVSS 7.1
CVE-2025-53099 HIGH
Sentry <25.5.0 - Auth Bypass
CVSS 7.5
CVE-2025-25171 HIGH
ThemesGrove WP SmartPay <2.7.13 - Auth Bypass
CVSS 8.8
CVE-2025-6688 CRITICAL
Idokd Simple Payment < 2.3.9 - Authentication Bypass
CVSS 9.8
CVE-2025-6675 MEDIUM
Miniorange 2fa < 4.8.0 - Authentication Bypass
CVSS 4.8
CVE-2025-6556 MEDIUM
Google Chrome <138.0.7204.49 - Auth Bypass
CVSS 5.4
CVE-2025-32976 HIGH
Quest KACE SMA <14.1.101 (Patch 4) - Auth Bypass
CVSS 8.8
CVE-2025-5820 HIGH
Sony XAV-AX8500 - Auth Bypass
CVSS 8.8
CVE-2025-51381 CRITICAL
KCM3100 <Ver1.4.2 - Auth Bypass
CVSS 9.8
CVE-2025-49125 HIGH
Apache Tomcat < 9.0.106 - Authentication Bypass
CVSS 7.5
CVE-2025-4973 CRITICAL
Amentotech Workreap < 3.3.2 - Authentication Bypass
CVSS 9.8
CVE-2025-30184 CRITICAL
CyberData 011209 Intercom - Info Disclosure
CVSS 9.8
CVE-2025-31022 CRITICAL
PayU PayU India <3.8.8 - Auth Bypass
CVSS 9.8
CVE-2025-31019 HIGH
miniOrange Password Policy Manager <2.0.4 - Auth Bypass
CVSS 8.8
CVE-2025-48904 MEDIUM
FRS - Privilege Escalation
CVSS 4.4
CVE-2025-4797 CRITICAL
Golo - City Travel Guide WordPress Theme <1.7.0 - Privilege Escalation
CVSS 9.8
CVE-2025-5190 HIGH
Browse As plugin <0.2 - Auth Bypass
CVSS 8.8
CVE-2025-4687 HIGH
Teltonika Networks RMS <5.7 - Privilege Escalation
CVE-2025-48926 MEDIUM
TeleMessage - Info Disclosure
CVSS 4.3
CVE-2025-47461 HIGH
mediaticus Subaccounts for WooCommerce <1.6.6 - Auth Bypass
CVSS 8.8
CVE-2025-34026 HIGH KEV
Versa Concerto <12.2.0 - Auth Bypass
CVSS 7.5
CVE-2025-46412 CRITICAL
Vertiv - Auth Bypass
CVSS 9.8
Details
Vulnerabilities 522