CWE-288

Authentication Bypass Using an Alternate Path or Channel

Parent: CWE-306 - Missing Authentication for Critical Function

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

612 vulnerabilities with CWE-288
CVE-2025-69101 CRITICAL
AmentoTech Workreap Core <3.4.0 - Auth Bypass
CVSS 9.8
CVE-2025-10484 CRITICAL
WooCommerce Registration & Login with Mobile Phone Number <= 1.3.1 - Authentication Bypass
CVSS 9.8
CVE-2025-68707 HIGH
Tongyu AX1800 Wi-Fi 6 Router 1.0.0 - Auth Bypass
CVSS 8.8
CVE-2025-46286 MEDIUM
iPadOS < 26.2 - Authentication Bypass via Backup Restore
CVSS 4.3
CVE-2025-67070 HIGH
Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T - Auth Bypass
CVSS 8.2
CVE-2025-67282 MEDIUM
TIM BPM Suite/TIM FLOW <9.1.2 - Privilege Escalation
CVSS 5.4
CVE-2025-67915 HIGH
Arraytics Timetics <1.0.47 - Auth Bypass
CVSS 8.8
CVE-2025-23504 CRITICAL
RiceTheme Felan Framework <1.1.4 - Auth Bypass
CVSS 9.8
CVE-2025-3652 MEDIUM
Petlibro < 1.7.31 - Unauthenticated Audio Recording Access via Insecure API Endpoint
CVSS 5.3
CVE-2025-64121 CRITICAL
Nuvation Energy MSC <2.5.1 - Auth Bypass
CVSS 9.8
CVE-2025-68620 CRITICAL
Signal K Server <2.19.0 - Auth Bypass
CVSS 9.1
CVE-2025-15102 CRITICAL
DVP-12SE11T Firmware < 2.16 - Authentication Bypass via Password Protection Bypass
CVSS 9.1
CVE-2025-68860 CRITICAL
Mobile builder <1.4.2 - Auth Bypass
CVSS 9.8
CVE-2025-64236 CRITICAL
AmentoTech Tuturn <3.6 - Auth Bypass
CVSS 9.8
CVE-2025-14714 MEDIUM
LibreOffice 25.2.0.1-25.2.4.1 - Authentication Bypass via Bundled Python Interpreter
CVSS 6.5
CVE-2025-11984 MEDIUM
GitLab CE/EE <18.4.6-18.6.2 - Auth Bypass
CVSS 6.8
CVE-2025-67507 HIGH
filament 4.0.0-4.3.0 - Authentication Bypass via Recovery Code Reuse
CVSS 8.1
CVE-2025-66200 MEDIUM
Apache HTTP Server <2.4.66 - Auth Bypass
CVSS 5.4
CVE-2025-66238 HIGH
Sunbird DCIM dcTrack < 9.2.0 and >= 9.2.3 - Authenticated Network Traffic Redirection via Virtual Console
CVSS 7.2
CVE-2025-13539 CRITICAL
FindAll Membership <1.0.4 - Auth Bypass
CVSS 9.8
CVE-2025-10571 CRITICAL
ABB Ability Edgenius <3.2.1.1 - Auth Bypass
CVSS 9.6
CVE-2025-63217 CRITICAL
Itel ID MUX Firmware - Authentication Bypass via JWT Token Reuse
CVSS 9.8
CVE-2025-12760 MEDIUM
Drupal Email TFA <2.0.6 - Auth Bypass
CVSS 5.4
CVE-2025-64530 HIGH
Apollo Federation <2.9.5-2.12.1 - Auth Bypass
CVSS 7.5
CVE-2025-59367 CRITICAL
ASUS DSL-AC51, DSL-N16, and DSL-AC750 Firmware < 1.1.2.3_1010 - Unauthenticated Authentication Bypass
CVSS 9.8
Details
Vulnerabilities 612