Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

607 CVEs tagged with CWE-288252 Critical, 218 High, 125 Medium, 12 Low, 0 Unrated.

CVE-2025-0364

Published Feb 4, 2025

BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker c…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
25.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-12857

Published Jan 22, 2025

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's iden…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24456

Published Jan 21, 2025

In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13181

Published Jan 14, 2025

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-13179

Published Jan 14, 2025

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-55591

Published Jan 14, 2025

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and…

CVSS 9.8 · Critical
evidence mentions
24
Buzz score
72.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-12402

Published Jan 7, 2025

The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i…

CVSS 9.8 · Critical

CVE-2024-51464

Published Dec 21, 2024

IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11349

Published Dec 21, 2024

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's iden…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-43234

Published Dec 16, 2024

Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authentication Bypass.This issue affects Woffice: from n/a through <= 5.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-56013

Published Dec 16, 2024

Authentication Bypass Using an Alternate Path or Channel vulnerability in wovax Wovax IDX wovax-idx allows Authentication Bypass.This issue affects Wovax IDX: from n/a through <=…

CVSS 8.8 · High

CVE-2024-54336

Published Dec 13, 2024

Authentication Bypass Using an Alternate Path or Channel vulnerability in Projectopia Projectopia projectopia-core allows Authentication Bypass.This issue affects Projectopia: fro…

CVSS 8.8 · High

CVE-2024-54297

Published Dec 13, 2024

Authentication Bypass Using an Alternate Path or Channel vulnerability in extremeidea vBSSO-lite vbsso-lite allows Authentication Bypass.This issue affects vBSSO-lite: from n/a th…

CVSS 9.8 · Critical

CVE-2024-54296

Published Dec 13, 2024

Authentication Bypass Using an Alternate Path or Channel vulnerability in Codexpert, Inc CoSchool LMS coschool allows Authentication Bypass.This issue affects CoSchool LMS: from n…

CVSS 9.8 · Critical

CVE-2024-54295

Published Dec 13, 2024

Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder ListApp Mobile Manager listapp-mobile-manager allows Authentication Bypass.This issue affects…

CVSS 9.8 · Critical

CVE-2024-54294

Published Dec 13, 2024

Authentication Bypass Using an Alternate Path or Channel vulnerability in Appgenix Infotech Firebase OTP Authentication authentication-via-otp-using-firebase allows Authentication…

CVSS 9.8 · Critical

CVE-2024-11639

Published Dec 10, 2024

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-52586

Published Dec 9, 2024

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11178

Published Dec 6, 2024

The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. This is due to the plugin generating too weak OTP, and ther…

CVSS 8.1 · High

CVE-2024-25036

Published Dec 3, 2024

IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input fie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10490

Published Dec 2, 2024

An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0,…

CVSS 8.4 · High

CVE-2024-11981

Published Nov 29, 2024

Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.

CVSS 7.5 · High

CVE-2024-52475

Published Nov 28, 2024

Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-platform allows Authentication Bypass.This issue affects Wawp:…

CVSS 9.8 · Critical

CVE-2024-11925

Published Nov 28, 2024

The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying…

CVSS 9.8 · Critical
Showing 351-375 of 607 CVEsPage 15 of 25