Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

605 CVEs tagged with CWE-288252 Critical, 217 High, 124 Medium, 12 Low, 0 Unrated.

CVE-2025-40761

Published Aug 12, 2025

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (All versions), RUGGEDCOM ROX RX1500 (All v…

CVSS 8.6 · High

CVE-2025-40743

Published Aug 12, 2025

A vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versions < V5.25 SP1), SINUMERIK 840D sl (All versions < V4.95 SP…

CVSS 8.7 · High

CVE-2025-55012

Published Aug 11, 2025

Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Remote Code Execution (RCE) by bypassing user permission chec…

CVSS 8.5 · High

CVE-2025-53187

Published Aug 11, 2025

Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication.…

CVSS 9.3 · Critical

CVE-2025-24000

Published Aug 7, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authentication Bypass.This issue affects Post SMTP: from n/a throug…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-7710

Published Aug 2, 2025

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly r…

CVSS 9.8 · Critical

CVE-2025-6895

Published Jul 26, 2025

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versio…

CVSS 9.8 · Critical

CVE-2025-7742

Published Jul 25, 2025

An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to upload an HTTP POST request to the devices non-volatile st…

CVSS 8.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-31512

Published Jul 22, 2025

An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover in a Request%20Building%20Access requestSubmit API call. Th…

CVSS 7.3 · High

CVE-2025-34143

Published Jul 22, 2025

An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal SYSTEM user by manipulating the…

CVSS 9.3 · Critical

CVE-2025-7692

Published Jul 22, 2025

The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the olws_handle_verify_phone() fun…

CVSS 8.1 · High

CVE-2025-7444

Published Jul 18, 2025

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insufficient verification on the user be…

CVSS 9.8 · Critical

CVE-2025-1313

Published Jul 12, 2025

The Nokri - Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.3. This is due to th…

CVSS 8.8 · High

CVE-2025-24332

Published Jul 2, 2025

Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after performing a single login to the baseband system board. The base…

CVSS 7.1 · High

CVE-2025-53099

Published Jul 1, 2025

Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25171

Published Jun 27, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Convers Lab WP SmartPay smartpay allows Authentication Abuse.This issue affects WP SmartPay: from n/a thr…

CVSS 8.8 · High

CVE-2025-6688

Published Jun 27, 2025

The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying a user's identity prior…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-6675

Published Jun 26, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - T…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6556

Published Jun 24, 2025

Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium se…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32976

Published Jun 24, 2025

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-5820

Published Jun 21, 2025

Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX85…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-51381

Published Jun 18, 2025

An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an attacker may bypass the authentication of the product from wi…

CVSS 9.3 · Critical
Showing 251-275 of 605 CVEsPage 11 of 25