Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

607 CVEs tagged with CWE-288252 Critical, 218 High, 125 Medium, 12 Low, 0 Unrated.

CVE-2025-5820

Published Jun 21, 2025

Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX85…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-51381

Published Jun 18, 2025

An authentication bypass vulnerability exists in KCM3100 Ver1.4.2 and earlier. If this vulnerability is exploited, an attacker may bypass the authentication of the product from wi…

CVSS 9.3 · Critical

CVE-2025-49125

Published Jun 16, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web applic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-4973

Published Jun 12, 2025

The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authentication bypass in all versions up to, and including, 3.3.1…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-31022

Published Jun 9, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in PayU India PayU India payu-india allows Authentication Abuse.This issue affects PayU India: from n/a thro…

CVSS 9.8 · Critical

CVE-2025-31019

Published Jun 9, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager password-policy-manager allows Authentication Abuse.This issue affects…

CVSS 8.8 · High

CVE-2025-48904

Published Jun 6, 2025

Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4797

Published Jun 3, 2025

The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is du…

CVSS 9.8 · Critical

CVE-2025-5190

Published May 30, 2025

The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is due to incorrect authentication checking in the 'IS_BA_Bro…

CVSS 8.8 · High

CVE-2025-4687

Published May 29, 2025

In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the invite functionality. If a victim has a pending invite and re…

CVSS 7.2 · High

CVE-2025-48926

Published May 28, 2025

The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47461

Published May 23, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce subaccounts-for-woocommerce allows Authentication Abuse.This issue…

CVSS 8.8 · High

CVE-2025-34026

Published May 21, 2025

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrativ…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-46412

Published May 21, 2025

Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.

CVSS 9.3 · Critical

CVE-2025-47941

Published May 20, 2025

TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS and the 13.x branch prior to 13.4.2 LTS, the multifactor auth…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33939

Published May 19, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47710

Published May 14, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - T…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47707

Published May 14, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - T…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3932

Published May 14, 2025

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The conf…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4427

Published May 13, 2025

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via th…

CVSS 5.3 · Medium
evidence mentions
16
Buzz score
67.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-22462

Published May 13, 2025

An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to ga…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 276-300 of 607 CVEsPage 12 of 25