CWE-288: CWE-288
Yearly Trend
Top Affected Vendors
All CWE-288 CVEs (236)
This vulnerability allows attackers to bypass authentication on Siemens SINUMERIK CNC systems' VNC access service due to insufficient password verific...
Aug 12, 2025This vulnerability allows unauthenticated attackers to bypass multi-factor authentication during password recovery on Intelbras CFTV IP cameras. Attac...
Jan 9, 2026The LatePoint WordPress plugin contains an authentication bypass vulnerability that allows unauthenticated attackers to log into any customer account ...
Sep 30, 2025CVE-2024-1646 is an authentication bypass vulnerability in parisneo/lollms-webui that allows unauthorized access to sensitive endpoints. Attackers can...
Apr 16, 2024CVE-2024-26566 is an authentication bypass vulnerability in Cute Http File Server v3.1 that allows remote attackers to escalate privileges by exploiti...
Mar 7, 2024This vulnerability allows unauthenticated attackers to bypass authentication in WordPress sites using the User Registration & Membership plugin. Attac...
Feb 26, 2026This CVE describes a mitigation bypass vulnerability in the DOM Security component of Mozilla products. It allows attackers to circumvent security con...
Nov 11, 2025This vulnerability allows authentication bypass in HashiCorp Vault's AWS Auth method when the bound_principal_iam role is identical across AWS account...
Oct 23, 2025The Service Finder SMS System WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user ...
Sep 19, 2025The Bravis User plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as administrative user...
Aug 23, 2025This CVE describes an authentication bypass vulnerability in Fortinet FortiOS, FortiProxy, and FortiPAM products that allows unauthenticated attackers...
Aug 12, 2025The Orion Login with SMS WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, incl...
Jul 22, 2025This vulnerability in Drupal's Two-factor Authentication (TFA) module allows attackers to bypass 2FA through forceful browsing techniques. It affects ...
Mar 31, 2025The Homey WordPress theme has an authentication bypass vulnerability that allows unauthenticated attackers to log in as the first verified user. This ...
Mar 7, 2025The Login Me Now WordPress plugin versions up to 1.7.2 contain an authentication bypass vulnerability that allows unauthenticated attackers to log in ...
Feb 27, 2025This authentication bypass vulnerability in FortiOS and FortiProxy allows remote unauthenticated attackers to gain super-admin privileges on downstrea...
Feb 11, 2025The Miniorange OTP Verification with Firebase WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log...
Oct 17, 2024This CVE describes an authentication bypass vulnerability in JetBrains TeamCity CI/CD servers. Attackers could potentially gain unauthorized access to...
May 29, 2024This vulnerability allows attackers to bypass authentication in affected products configured for Single Sign-On (SSO). By manually entering any Active...
Dec 15, 2021CVE-2023-1260 is an authentication bypass vulnerability in Kubernetes kube-apiserver that allows authenticated attackers with specific permissions to ...
Sep 24, 2023CVE-2024-41173 is a local authentication bypass vulnerability in the IPC-Diagnostics package of TwinCAT/BSD. A low-privileged local attacker can bypas...
Aug 27, 2024CVE-2024-7125 is an authentication bypass vulnerability in Hitachi Ops Center Common Services that allows attackers to bypass authentication mechanism...
Aug 27, 2024This CVE describes an authentication bypass vulnerability in Veeam Agent for Microsoft Windows that allows local attackers to escalate privileges. Att...
May 22, 2024This vulnerability allows local attackers to load arbitrary code into the Android System Settings app due to a confused deputy flaw in AccountManagerS...
Apr 19, 2023This CVE describes an authentication bypass vulnerability in multiple Apple operating systems where an attacker on the local network can circumvent au...
Apr 29, 2025CVE-2021-41995 is a vulnerability in PingID Mac Login that allows attackers to bypass multi-factor authentication through pre-computed dictionary atta...
Jun 30, 2022This CVE describes an MFA bypass vulnerability in PingFederate's PingOne MFA Integration Kit when using adapter HTML templates in authentication flows...
May 2, 2022This vulnerability allows applications to bypass privacy preferences on affected Apple operating systems. It affects users running visionOS, iOS, and ...
Mar 31, 2025This vulnerability in Apollo Federation allows GraphQL queries to bypass access controls on interface types/fields by querying implementing object typ...
Nov 13, 2025This vulnerability in Apollo Router Core allows unauthenticated GraphQL queries to bypass access controls on polymorphic types when @authenticated, @r...
Nov 6, 2025This CVE describes an authentication bypass vulnerability in Apache Kylin that allows attackers to access protected functionality without proper crede...
Oct 2, 2025This CVE describes an OAuth authorization flaw in Sentry where attackers with malicious OAuth applications can exploit a race condition to maintain pe...
Jul 1, 2025This CVE describes an authentication bypass vulnerability in Apache Tomcat where PreResources or PostResources mounted at non-root paths can be access...
Jun 16, 2025This CVE describes an authentication bypass vulnerability in the Versa Concerto SD-WAN orchestration platform's Traefik reverse proxy configuration. A...
May 21, 2025This vulnerability allows attackers to bypass multi-factor authentication in Drupal Enterprise MFA - TFA modules, potentially gaining unauthorized acc...
May 14, 2025This CVE describes an authentication bypass vulnerability in certain Billion Electric router models that allows unauthenticated attackers to access ar...
Nov 29, 2024The eHRD CTMS from Sunnet has an authentication bypass vulnerability that allows unauthenticated remote attackers to access restricted functionalities...
Oct 28, 2024This vulnerability allows attackers to gain administrative access to OpenBMC systems by exploiting default passwords and session management weaknesses...
Aug 13, 2024This CVE describes an authentication bypass vulnerability in HPE iLO 5 and iLO 6 remote management controllers. Attackers could potentially gain unaut...
Dec 19, 2023This vulnerability allows attackers to bypass first-factor authentication in PingFederate with PingID Radius PCV by sending maliciously crafted RADIUS...
Oct 25, 2023This vulnerability allows unauthenticated attackers to bypass access controls on WALLIX Bastion's network access administration web interface, exposin...
Oct 23, 2023PingID Windows Login versions before 2.8 fail to warn or stop when configured with full-permission API credentials meant for administrative systems li...
Jun 30, 2022CVE-2021-28131 is an authentication bypass vulnerability in Apache Impala where session secrets are exposed in logs, allowing authenticated users to h...
Jul 22, 2021This vulnerability allows attackers to bypass multi-factor authentication in Drupal Enterprise MFA - TFA modules, potentially gaining unauthorized acc...
May 14, 2025This vulnerability in Inedo ProGet allows remote attackers to access restricted functionality through the C# reflection layer, potentially causing den...
May 3, 2025The WooCommerce Social Login plugin for WordPress has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any no...
Jul 20, 2024This vulnerability in PingFederate with PingOne MFA adapter allows attackers who have compromised a user's first-factor credentials (like username/pas...
Oct 25, 2023PingID Desktop versions before 1.7.4 contain an authentication bypass vulnerability where attackers can circumvent the maximum PIN attempt limit befor...
Apr 25, 2023This vulnerability in DCIM dcTrack allows authenticated users with virtual console access to misuse remote access features for network traffic redirec...
Dec 4, 2025CVE-2022-1681 is an authentication bypass vulnerability in Wiki.js that allows attackers to gain root user permissions through an alternate path or ch...
May 12, 2022About CWE-288 (CWE-288)
Our database tracks 236 CVEs classified as CWE-288, with 130 rated critical and 74 rated high severity. The average CVSS score for CWE-288 vulnerabilities is 8.7.
External reference: View CWE-288 on MITRE CWE →
Monitor CWE-288 Vulnerabilities
Get alerted when new CWE-288 CVEs affect your infrastructure.
Start Monitoring Free