Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

605 CVEs tagged with CWE-288252 Critical, 217 High, 124 Medium, 12 Low, 0 Unrated.

CVE-2025-10653

Published Oct 2, 2025

An unauthenticated debug port may allow access to the device file system.

CVSS 8.6 · High

CVE-2025-22862

Published Oct 2, 2025

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 thr…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61733

Published Oct 2, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-10538

Published Oct 1, 2025

An authentication bypass vulnerability exists in LG Innotek camera models LND7210 and LNV7210R. The vulnerability allows a malicious actor to gain access to camera information inc…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-7038

Published Sep 30, 2025

The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification within the steps__load_step route of the latepoint_route_call A…

CVSS 8.2 · High

CVE-2025-5955

Published Sep 19, 2025

The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.0. This is due to the plugin not verifying a us…

CVSS 8.1 · High

CVE-2023-49564

Published Sep 18, 2025

The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a specially crafted HTTP header, an unauthenticated user can gain unauthorized access to API functio…

CVSS 8.8 · High

CVE-2025-10531

Published Sep 16, 2025

Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-8359

Published Sep 6, 2025

The AdForest theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.9. This is due to the plugin not properly verifying a user's iden…

CVSS 9.8 · Critical

CVE-2025-57819

Published Aug 28, 2025

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthent…

CVSS 10.0 · Critical
evidence mentions
4
Buzz score
63.6
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-54738

Published Aug 28, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Authentication Abuse.This issue affects Jobmonster: from n/a th…

CVSS 9.8 · Critical

CVE-2025-54725

Published Aug 28, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.This issue affects Golo: from n/a through <= 1.7.0.

CVSS 9.8 · Critical

CVE-2025-34520

Published Aug 27, 2025

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user ac…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5821

Published Aug 23, 2025

The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly logging in a us…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-5060

Published Aug 23, 2025

The Bravis User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly logging a user in w…

CVSS 8.1 · High

CVE-2025-7642

Published Aug 23, 2025

The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a user's identity pri…

CVSS 9.8 · Critical

CVE-2025-55623

Published Aug 22, 2025

An issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using an ADB (Android Debug Bridge).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50904

Published Aug 20, 2025

There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27129

Published Aug 20, 2025

An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24496

Published Aug 20, 2025

An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted network packets can lead to a disclos…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54713

Published Aug 20, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Authentication Abuse…

CVSS 9.8 · Critical

CVE-2025-52338

Published Aug 19, 2025

An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user acc…

CVSS 5.3 · Medium

CVE-2025-3639

Published Aug 18, 2025

Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1…

CVSS 2.0 · Low
Showing 226-250 of 605 CVEsPage 10 of 25