Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

607 CVEs tagged with CWE-288252 Critical, 218 High, 125 Medium, 12 Low, 0 Unrated.

CVE-2025-0549

Published May 9, 2025

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vu…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-3844

Published May 7, 2025

The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Authentication Bypass in versions 1.9.1 to 7.5.2. This is due to handel_ajax_req() function not havin…

CVSS 9.8 · Critical

CVE-2024-12225

Published May 6, 2025

A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in whi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-45607

Published May 5, 2025

An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-1909

Published May 5, 2025

The BuddyBoss Platform Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.01. This is due to insufficient verification on the us…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-47244

Published May 3, 2025

Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an att…

CVSS 7.3 · High

CVE-2025-2492

Published Apr 18, 2025

An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of func…

CVSS 9.2 · Critical
evidence mentions
7
Buzz score
33.8

CVE-2024-42178

Published Apr 17, 2025

HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creatin…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-39535

Published Apr 17, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authentication Abuse.This issue affects Vitepos: from n/a through <= 3…

CVSS 7.2 · High

CVE-2025-32357

Published Apr 5, 2025

In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission fo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-56325

Published Apr 1, 2025

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-T…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-31095

Published Apr 1, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Hossein Material Dashboard material-dashboard allows Authentication Bypass.This issue affects Material Da…

CVSS 9.8 · Critical

CVE-2025-22277

Published Apr 1, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authentication Abuse.This issue affects Vitepos: from n/a through <= 3…

CVSS 8.8 · High

CVE-2025-22230

Published Mar 25, 2025

VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious actor with non-administrative privileges on a guest VM may gai…

CVSS 7.8 · High
evidence mentions
4
Buzz score
24.1

CVE-2025-2747

Published Mar 24, 2025

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type.…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
49.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-2746

Published Mar 24, 2025

An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentica…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
49.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-30112

Published Mar 24, 2025

On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorizatio…

CVSS 7.1 · High

CVE-2024-13442

Published Mar 19, 2025

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.0. This is due to the plugin no…

CVSS 9.8 · Critical

CVE-2024-13772

Published Mar 14, 2025

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13771

Published Mar 14, 2025

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-11286

Published Mar 14, 2025

The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. This is due to the plugin not properly verifying a user's ide…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 301-325 of 607 CVEsPage 13 of 25