CWE-288
659 CVEs • Abstraction: Base
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
CVEs (659)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST AP...Show more |
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API requ...Show more |
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through...Show more |
1Cisco 8Business 140ac Access Point Firmware Business 141acm FirmwareBusiness 142acm Firmware+5 moreJun 17, 2026 May 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login authentication. This vu...Show more |
The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social logi...Show more |
1Selinc 10Sel 2241 Rtac Module Firmware Sel 3350 FirmwareSel 3505 3 Firmware+7 moreJun 17, 2026 May 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An Authentication Bypass Using an Alternate Path or Channel vulnerability in the Schweitzer Engineering Laboratories Real-Time Automation Controller (SEL RTAC) Web Interface allows Authentication Bypass. See SEL Service...Show more |
PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is activated. |
In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additiona...Show more |
1Zm Ajax Login & Register Project 1Zm Ajax Login & Register Jun 17, 2026 Apr 15, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook logi...Show more |
1Apple 5Ipados Iphone OsMacos+2 moreJun 17, 2026 Feb 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3, iOS 15.7.3 and iPadOS 15.7.3, tvOS 16.3, watchOS 9.3. An app may be able to bypass Privacy...Show more |
1Cisco 22Ip Phone 7800 Firmware Ip Phone 7811 FirmwareIp Phone 7821 Firmware+19 moreJun 17, 2026 Jan 20, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is...Show more |
Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypass the authentication in this application when deployed using the official Docker image. Because a ha...Show more |
NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of ser...Show more |
NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of servic...Show more |
NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a loss of integrity and denial of service. |
In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation. |
1Zohocorp 1Manageengine Device Control Plus Jun 17, 2026 Dec 20, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections t...Show more |
1Citrix 2Application Delivery Controller Firmware GatewayJun 17, 2026 Nov 8, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Unauthorized access to Gateway user capabilities
|
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability under specific configuration. An attacker would gain unautho...Show more |
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform v...Show more |