Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

612 CVEs tagged with CWE-288255 Critical, 219 High, 126 Medium, 12 Low, 0 Unrated.

CVE-2026-8338

Published Jul 29, 2026

A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can sen…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12703

Published Jul 29, 2026

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections a…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18047

Published Jul 28, 2026

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trail…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-15014

Published Jul 28, 2026

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
27.3

CVE-2026-61884

Published Jul 24, 2026

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2026-59545

Published Jul 23, 2026

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59524

Published Jul 23, 2026

Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-22049

Published Jul 22, 2026

ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfu…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-43945

Published Jul 21, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Executio…

CVSS 8.9 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-61425

Published Jul 20, 2026

Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin a…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-39385

Published Jul 20, 2026

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16198

Published Jul 19, 2026

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component Firs…

CVSS 2.9 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-57980

Published Jul 17, 2026

Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47481

Published Jul 14, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-57698

Published Jul 13, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abus…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-57697

Published Jul 13, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploita…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57807

Published Jul 10, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-36028

Published Jul 8, 2026

A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-57867

Published Jul 7, 2026

MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-f…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-5268

Published Jul 6, 2026

An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated a…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-13475

Published Jul 4, 2026

In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific Saa…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-58517

Published Jul 1, 2026

Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-12579

Published Jul 1, 2026

AS228T with Authentication Bypass Vulnerability

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-20460

Published Jul 1, 2026

In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has connected to a rogue base stat…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-20459

Published Jul 1, 2026

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 612 CVEsPage 1 of 25