CWE-288: CWE-288

236
Total CVEs
130
Critical
74
High
8.7
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
29
2025
117
2024
61
2023
11
2022
11

Top Affected Vendors

1 Pingidentity 6
2 Fortinet 5
3 Ibm 5
4 Jetbrains 4
5 Mozilla 4
6 Apache 4
7 Ivanti 4
8 Miniorange 4
9 Automationdirect 3
10 Google 3

All CWE-288 CVEs (236)

CVE-2025-40743
8.3

This vulnerability allows attackers to bypass authentication on Siemens SINUMERIK CNC systems' VNC access service due to insufficient password verific...

Aug 12, 2025
CVE-2025-67070
8.2

This vulnerability allows unauthenticated attackers to bypass multi-factor authentication during password recovery on Intelbras CFTV IP cameras. Attac...

Jan 9, 2026
CVE-2025-7038
8.2

The LatePoint WordPress plugin contains an authentication bypass vulnerability that allows unauthenticated attackers to log into any customer account ...

Sep 30, 2025
CVE-2024-1646
8.2

CVE-2024-1646 is an authentication bypass vulnerability in parisneo/lollms-webui that allows unauthorized access to sensitive endpoints. Attackers can...

Apr 16, 2024
CVE-2024-26566
8.2

CVE-2024-26566 is an authentication bypass vulnerability in Cute Http File Server v3.1 that allows remote attackers to escalate privileges by exploiti...

Mar 7, 2024
CVE-2026-1779
8.1

This vulnerability allows unauthenticated attackers to bypass authentication in WordPress sites using the User Registration & Membership plugin. Attac...

Feb 26, 2026
CVE-2025-13018
8.1

This CVE describes a mitigation bypass vulnerability in the DOM Security component of Mozilla products. It allows attackers to circumvent security con...

Nov 11, 2025
CVE-2025-11621
8.1

This vulnerability allows authentication bypass in HashiCorp Vault's AWS Auth method when the bound_principal_iam role is identical across AWS account...

Oct 23, 2025
CVE-2025-5955
8.1

The Service Finder SMS System WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user ...

Sep 19, 2025
CVE-2025-5060
8.1

The Bravis User plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as administrative user...

Aug 23, 2025
CVE-2024-26009
8.1

This CVE describes an authentication bypass vulnerability in Fortinet FortiOS, FortiProxy, and FortiPAM products that allows unauthenticated attackers...

Aug 12, 2025
CVE-2025-7692
8.1

The Orion Login with SMS WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, incl...

Jul 22, 2025
CVE-2025-31694
8.1

This vulnerability in Drupal's Two-factor Authentication (TFA) module allows attackers to bypass 2FA through forceful browsing techniques. It affects ...

Mar 31, 2025
CVE-2025-0749
8.1

The Homey WordPress theme has an authentication bypass vulnerability that allows unauthenticated attackers to log in as the first verified user. This ...

Mar 7, 2025
CVE-2025-1717
8.1

The Login Me Now WordPress plugin versions up to 1.7.2 contain an authentication bypass vulnerability that allows unauthenticated attackers to log in ...

Feb 27, 2025
CVE-2025-24472
KEV 8.1

This authentication bypass vulnerability in FortiOS and FortiProxy allows remote unauthenticated attackers to gain super-admin privileges on downstrea...

Feb 11, 2025
CVE-2024-9861
8.1

The Miniorange OTP Verification with Firebase WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log...

Oct 17, 2024
CVE-2024-36470
8.1

This CVE describes an authentication bypass vulnerability in JetBrains TeamCity CI/CD servers. Attackers could potentially gain unauthorized access to...

May 29, 2024
CVE-2021-43935
8.1

This vulnerability allows attackers to bypass authentication in affected products configured for Single Sign-On (SSO). By manually entering any Active...

Dec 15, 2021
CVE-2023-1260
8.0

CVE-2023-1260 is an authentication bypass vulnerability in Kubernetes kube-apiserver that allows authenticated attackers with specific permissions to ...

Sep 24, 2023
CVE-2024-41173
7.8

CVE-2024-41173 is a local authentication bypass vulnerability in the IPC-Diagnostics package of TwinCAT/BSD. A low-privileged local attacker can bypas...

Aug 27, 2024
CVE-2024-7125
7.8

CVE-2024-7125 is an authentication bypass vulnerability in Hitachi Ops Center Common Services that allows attackers to bypass authentication mechanism...

Aug 27, 2024
CVE-2024-29853
7.8

This CVE describes an authentication bypass vulnerability in Veeam Agent for Microsoft Windows that allows local attackers to escalate privileges. Att...

May 22, 2024
CVE-2023-21098
7.8

This vulnerability allows local attackers to load arbitrary code into the Android System Settings app due to a confused deputy flaw in AccountManagerS...

Apr 19, 2023
CVE-2025-24206
7.7

This CVE describes an authentication bypass vulnerability in multiple Apple operating systems where an attacker on the local network can circumvent au...

Apr 29, 2025
CVE-2021-41995
7.7

CVE-2021-41995 is a vulnerability in PingID Mac Login that allows attackers to bypass multi-factor authentication through pre-computed dictionary atta...

Jun 30, 2022
CVE-2022-23723
7.7

This CVE describes an MFA bypass vulnerability in PingFederate's PingOne MFA Integration Kit when using adapter HTML templates in authentication flows...

May 2, 2022
CVE-2025-24095
7.6

This vulnerability allows applications to bypass privacy preferences on affected Apple operating systems. It affects users running visionOS, iOS, and ...

Mar 31, 2025
CVE-2025-64530
7.5

This vulnerability in Apollo Federation allows GraphQL queries to bypass access controls on interface types/fields by querying implementing object typ...

Nov 13, 2025
CVE-2025-64173
7.5

This vulnerability in Apollo Router Core allows unauthenticated GraphQL queries to bypass access controls on polymorphic types when @authenticated, @r...

Nov 6, 2025
CVE-2025-61733
7.5

This CVE describes an authentication bypass vulnerability in Apache Kylin that allows attackers to access protected functionality without proper crede...

Oct 2, 2025
CVE-2025-53099
7.5

This CVE describes an OAuth authorization flaw in Sentry where attackers with malicious OAuth applications can exploit a race condition to maintain pe...

Jul 1, 2025
CVE-2025-49125
7.5

This CVE describes an authentication bypass vulnerability in Apache Tomcat where PreResources or PostResources mounted at non-root paths can be access...

Jun 16, 2025
CVE-2025-34026
KEV EPSS 58.5% 7.5

This CVE describes an authentication bypass vulnerability in the Versa Concerto SD-WAN orchestration platform's Traefik reverse proxy configuration. A...

May 21, 2025
CVE-2025-47707
7.5

This vulnerability allows attackers to bypass multi-factor authentication in Drupal Enterprise MFA - TFA modules, potentially gaining unauthorized acc...

May 14, 2025
CVE-2024-11981
7.5

This CVE describes an authentication bypass vulnerability in certain Billion Electric router models that allows unauthenticated attackers to access ar...

Nov 29, 2024
CVE-2024-10438
7.5

The eHRD CTMS from Sunnet has an authentication bypass vulnerability that allows unauthenticated remote attackers to access restricted functionalities...

Oct 28, 2024
CVE-2024-35124
7.5

This vulnerability allows attackers to gain administrative access to OpenBMC systems by exploiting default passwords and session management weaknesses...

Aug 13, 2024
CVE-2023-50272
7.5

This CVE describes an authentication bypass vulnerability in HPE iLO 5 and iLO 6 remote management controllers. Attackers could potentially gain unaut...

Dec 19, 2023
CVE-2023-39930
7.5

This vulnerability allows attackers to bypass first-factor authentication in PingFederate with PingID Radius PCV by sending maliciously crafted RADIUS...

Oct 25, 2023
CVE-2023-46319
7.5

This vulnerability allows unauthenticated attackers to bypass access controls on WALLIX Bastion's network access administration web interface, exposin...

Oct 23, 2023
CVE-2022-23720
7.5

PingID Windows Login versions before 2.8 fail to warn or stop when configured with full-permission API credentials meant for administrative systems li...

Jun 30, 2022
CVE-2021-28131
7.5

CVE-2021-28131 is an authentication bypass vulnerability in Apache Impala where session secrets are exposed in logs, allowing authenticated users to h...

Jul 22, 2021
CVE-2025-47710
7.4

This vulnerability allows attackers to bypass multi-factor authentication in Drupal Enterprise MFA - TFA modules, potentially gaining unauthorized acc...

May 14, 2025
CVE-2025-47244
7.3

This vulnerability in Inedo ProGet allows remote attackers to access restricted functionality through the C# reflection layer, potentially causing den...

May 3, 2025
CVE-2024-6635
7.3

The WooCommerce Social Login plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any no...

Jul 20, 2024
CVE-2023-39231
7.3

This vulnerability in PingFederate with PingOne MFA adapter allows attackers who have compromised a user's first-factor credentials (like username/pas...

Oct 25, 2023
CVE-2022-40725
7.3

PingID Desktop versions before 1.7.4 contain an authentication bypass vulnerability where attackers can circumvent the maximum PIN attempt limit befor...

Apr 25, 2023
CVE-2025-66238
7.2

This vulnerability in DCIM dcTrack allows authenticated users with virtual console access to misuse remote access features for network traffic redirec...

Dec 4, 2025
CVE-2022-1681
7.2

CVE-2022-1681 is an authentication bypass vulnerability in Wiki.js that allows attackers to gain root user permissions through an alternate path or ch...

May 12, 2022

About CWE-288 (CWE-288)

Our database tracks 236 CVEs classified as CWE-288, with 130 rated critical and 74 rated high severity. The average CVSS score for CWE-288 vulnerabilities is 8.7.

External reference: View CWE-288 on MITRE CWE →

Monitor CWE-288 Vulnerabilities

Get alerted when new CWE-288 CVEs affect your infrastructure.

Start Monitoring Free