Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

607 CVEs tagged with CWE-288252 Critical, 218 High, 125 Medium, 12 Low, 0 Unrated.

CVE-2025-2080

Published Mar 13, 2025

Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that could allow an attacker to bypa…

CVSS 9.3 · Critical

CVE-2025-29996

Published Mar 13, 2025

This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanism in its API based login. A remote attacker with valid cred…

CVSS 8.2 · High

CVE-2024-13446

Published Mar 12, 2025

The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.2.5. This is due to the plugin not properly va…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-1315

Published Mar 7, 2025

The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is due to the plugin not properly v…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-0749

Published Mar 7, 2025

The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is due to the 'verification_id' value being set to empty, and th…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-1515

Published Mar 5, 2025

The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. This is due to insufficient identity verification…

CVSS 9.8 · Critical

CVE-2025-24846

Published Mar 3, 2025

Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co., Ltd. If this vulnerability is exploited, a remote unauthent…

CVSS 7.5 · High

CVE-2025-1671

Published Mar 1, 2025

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_face…

CVSS 9.8 · Critical

CVE-2025-1638

Published Mar 1, 2025

The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating…

CVSS 9.8 · Critical

CVE-2025-1564

Published Mar 1, 2025

The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity throug…

CVSS 9.8 · Critical

CVE-2025-0159

Published Feb 28, 2025

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 th…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1739

Published Feb 27, 2025

An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's…

CVSS 7.1 · High

CVE-2025-1717

Published Feb 27, 2025

The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. This is due to insecure authentication based on an arbitrary…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26966

Published Feb 25, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.5.

CVSS 9.8 · Critical

CVE-2025-26700

Published Feb 17, 2025

Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with acce…

CVSS 5.2 · Medium

CVE-2024-13182

Published Feb 13, 2025

The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the '…

CVSS 9.8 · Critical

CVE-2025-24472

Published Feb 11, 2025

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.1…

CVSS 8.1 · High
evidence mentions
9
Buzz score
56.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-0181

Published Feb 11, 2025

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.8. This is due to the plugin not properly…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-0316

Published Feb 8, 2025

The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_d…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-1061

Published Feb 7, 2025

The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2025-0674

Published Feb 7, 2025

Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit t…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-23217

Published Feb 6, 2025

mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmweb 11.1.…

CVSS 8.2 · High
Showing 326-350 of 607 CVEsPage 14 of 25