CWE-305

Authentication Bypass by Primary Weakness

Parent: CWE-1390 - Weak Authentication

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

154 vulnerabilities with CWE-305
CVE-2025-31965 HIGH
HCL BigFix Remote Control Server WebUI <10.1.0.0248 - Info Disclosure
CVSS 8.2
CVE-2025-53826 CRITICAL
File Browser <2.39.0 - Info Disclosure
CVSS 9.8
CVE-2025-53167 MEDIUM
Distributed Collaboration Framework - Info Disclosure
CVSS 6.9
CVE-2025-52996 LOW
File Browser <2.32.0 - Info Disclosure
CVSS 3.1
CVE-2025-46801 CRITICAL
Pgpool-II 4.0-4.6 - Authentication Bypass
CVSS 9.8
CVE-2025-4658 CRITICAL
OpenPubkey < 0.10.0 and OPKSSH < 0.5.0 - Authentication Bypass via JWS Signature Verification
CVSS 9.8
CVE-2025-3757 CRITICAL
OpenPubkey < 0.10.0 - Authentication Bypass via JWS Signature Verification
CVSS 9.8
CVE-2025-46750 MEDIUM
SEL BIOS <1.3.49152.117, <2.6.49152.98 - Auth Bypass
CVSS 4.4
CVE-2025-41450 HIGH
Danfoss AKSM8xxA Series <4.2 - Auth Bypass
CVSS 8.2
CVE-2025-32011 CRITICAL
KUNBUS PiCtory <2.11.1 - Auth Bypass
CVSS 9.8
CVE-2025-24522 CRITICAL
KUNBUS Revolution Pi OS Bookworm 01/2025 - RCE
CVSS 10.0
CVE-2025-31161 CRITICAL KEV
CrushFTP - Authentication Bypass
CVSS 9.8
CVE-2025-31192 MEDIUM
Safari < 18.4 - Unauthenticated Sensor Information Access
CVSS 6.7
CVE-2025-30428 MEDIUM
iPadOS < 17.7.6 and < 18.4 - Unauthenticated Hidden Photos Album Access
CVSS 5.4
CVE-2025-1880 LOW
i-Drive i11<i12 <20250227 - Auth Bypass
CVSS 2.0
CVE-2025-27371 MEDIUM
IETF RFC 7523 - Authentication Bypass via Ambiguous JWT Audience Values
CVSS 6.9
CVE-2025-27370 MEDIUM
OpenID Connect Core <1.0 - Command Injection
CVSS 6.9
CVE-2025-23017 MEDIUM
WorkOS Hosted AuthKit <2025-01-07 - Auth Bypass
CVSS 6.0
CVE-2024-49587 CRITICAL
Palantir Glutton >=105.95.0 - Unauthenticated Authentication Bypass
CVSS 9.1
CVE-2024-12776 HIGH
langgenius/dify v0.10.1 - Unauthenticated Authentication Bypass via Password Reset Endpoint
CVSS 8.1
CVE-2024-12054 MEDIUM
ZF RSSPlus 2M 01/08-01/23 - Authentication Bypass via SecurityAccess Service Seed
CVSS 5.4
CVE-2024-42513 MEDIUM
OPC UA .NET Standard Stack <1.5.374.158 - Auth Bypass
CVSS 5.3
CVE-2024-51738 HIGH
lizardbyte/sunshine < 2025.118.151840 - Unauthenticated Authentication Bypass via Pairing Protocol MITM
CVSS 8.1
CVE-2024-12802 CRITICAL
SonicOS Authentication Bypass via UPN/SAM Account Name Handling
CVSS 9.1
CVE-2024-12582 HIGH
Service Interconnect 1 for RHEL 9 - Authentication Bypass and Denial of Service via Plaintext Password File
CVSS 7.1
Details
Vulnerabilities 154