CWE-288: CWE-288

236
Total CVEs
130
Critical
74
High
8.7
Avg CVSS
7
In CISA KEV

Yearly Trend

2026
29
2025
117
2024
61
2023
11
2022
11

Top Affected Vendors

1 Pingidentity 6
2 Fortinet 5
3 Ibm 5
4 Jetbrains 4
5 Mozilla 4
6 Apache 4
7 Ivanti 4
8 Miniorange 4
9 Automationdirect 3
10 Google 3

All CWE-288 CVEs (236)

CVE-2025-24332
7.1

This vulnerability allows authenticated administrative users on Nokia Single RAN AirScale baseband systems to access all physical boards after a singl...

Jul 2, 2025
CVE-2025-40581
7.1

This vulnerability allows local attackers to bypass authentication on Siemens SCALANCE LPE9403 devices with SINEMA Remote Connect Edge Client installe...

May 13, 2025
CVE-2025-30112
7.1

This vulnerability allows attackers to bypass the physical button pairing requirement on 70mai Dash Cam 1S devices by directly connecting to the devic...

Mar 24, 2025
CVE-2025-1739
7.1

An authentication bypass vulnerability in Trivision Camera NC227WF v5.8.0 allows attackers to retrieve administrator credentials in cleartext by sendi...

Feb 27, 2025
CVE-2025-11984
6.8

This vulnerability allows authenticated users to bypass WebAuthn two-factor authentication in GitLab by manipulating session state. It affects GitLab ...

Dec 11, 2025
CVE-2025-59392
6.8

This vulnerability allows physical attackers to reset the admin password on Elspec G5 devices by inserting a USB drive with a specific reset string. I...

Nov 6, 2025
CVE-2025-0549
6.8

This vulnerability allows attackers to bypass Device OAuth flow protections in GitLab, enabling unauthorized authorization form submissions with minim...

May 9, 2025
CVE-2025-22862
6.7

This CVE describes an authentication bypass vulnerability in FortiOS and FortiProxy that allows authenticated attackers to elevate privileges via mali...

Oct 2, 2025
CVE-2026-0948
6.5

This CVE describes an authentication bypass vulnerability in Drupal's Microsoft Entra ID SSO Login module that allows attackers to access privileged f...

Feb 4, 2026
CVE-2025-14714
6.5

This CVE describes an authentication bypass vulnerability in LibreOffice on macOS where the bundled Python interpreter inherits the main application's...

Dec 15, 2025
CVE-2025-12445
6.5

A policy bypass vulnerability in Google Chrome extensions allows malicious extensions to leak cross-origin data. Attackers can exploit this by convinc...

Nov 10, 2025
CVE-2025-12431
6.5

This vulnerability allows attackers to bypass Chrome's navigation restrictions by tricking users into installing a malicious extension. It affects all...

Nov 10, 2025
CVE-2024-35151
6.5

IBM OpenPages with Watson versions 8.3 and 9.0 contain an improper authorization vulnerability in APIs that allows authenticated users to access sensi...

Aug 22, 2024
CVE-2024-5620
6.5

This CVE describes an authentication bypass vulnerability in PruvaSoft Informatics Apinizer Management Console that allows attackers to access protect...

Jul 18, 2024
CVE-2025-13013
6.1

This CVE describes a mitigation bypass vulnerability in the DOM: Core & HTML component of Mozilla products. It allows attackers to bypass security mit...

Nov 11, 2025
CVE-2025-67282
5.4

Multiple authorization bypass vulnerabilities in TIM BPM Suite/TIM FLOW allow low-privileged users to access sensitive data and modify restricted cont...

Jan 9, 2026
CVE-2025-66200
5.4

This vulnerability allows users with htaccess file access to bypass mod_userdir+suexec restrictions via the RequestHeader directive, potentially causi...

Dec 5, 2025
CVE-2025-12760
5.4

This vulnerability allows attackers to bypass two-factor authentication (2FA) in Drupal's Email TFA module, potentially gaining unauthorized access to...

Nov 18, 2025
CVE-2025-10531
5.4

This CVE describes a mitigation bypass vulnerability in the Web Compatibility: Tooling component of Firefox and Thunderbird. Attackers could potential...

Sep 16, 2025
CVE-2025-55623
5.4

This vulnerability allows attackers to bypass the lock screen authentication on Reolink mobile apps by exploiting Android Debug Bridge (ADB) access. I...

Aug 22, 2025
CVE-2025-13980
5.3

This vulnerability allows attackers to bypass authentication mechanisms in Drupal CKEditor 5 Premium Features, potentially gaining unauthorized access...

Jan 28, 2026
CVE-2025-3652
5.3

The Petlibro Smart Pet Feeder Platform contains an information disclosure vulnerability that allows attackers to access private audio recordings of ot...

Jan 4, 2026
CVE-2025-58133
5.3

An authentication bypass vulnerability in Zoom Rooms Clients allows unauthenticated attackers to access sensitive information via network access. This...

Oct 15, 2025
CVE-2024-33939
5.3

This vulnerability allows unauthenticated attackers to access course progress data in Masteriyo LMS WordPress plugin without proper authentication. It...

May 19, 2025
CVE-2025-4427
KEV EPSS 90.8% 5.3

An authentication bypass vulnerability in Ivanti Endpoint Manager Mobile's API allows attackers to access protected resources without valid credential...

May 13, 2025
CVE-2024-50334
5.3

This CVE describes a semicolon path injection vulnerability in Scoold's API endpoint that allows unauthenticated attackers to bypass authentication an...

Oct 29, 2024
CVE-2026-30777
4.9

EC-CUBE contains an MFA bypass vulnerability that allows attackers with valid administrator credentials to circumvent two-factor authentication and ac...

Mar 5, 2026
CVE-2025-6675
4.8

This vulnerability allows attackers to bypass multi-factor authentication in Drupal Enterprise MFA - TFA for Drupal by using an alternate path or chan...

Jun 26, 2025
CVE-2025-48010
4.8

This CVE describes an authentication bypass vulnerability in the Drupal One Time Password module that allows attackers to bypass functionality by usin...

May 21, 2025
CVE-2024-38279
4.6

This vulnerability allows attackers to bypass authentication by modifying bootloader arguments, gaining access to the file system and password hashes....

Jun 13, 2024
CVE-2026-1747
4.3

This vulnerability allows Developer-role users in GitLab EE to make unauthorized modifications to protected Conan packages when they lack proper permi...

Feb 25, 2026
CVE-2025-9914
4.3

This vulnerability allows attackers to use stored user credentials from the local database to gain unauthorized access to affected systems. It affects...

Oct 6, 2025
CVE-2024-51464
4.3

This vulnerability allows authenticated IBM i users to bypass interface restrictions in Navigator for i by sending specially crafted requests. Attacke...

Dec 21, 2024
CVE-2025-13986
4.2

This vulnerability allows attackers to bypass authentication in Drupal sites using the Disable Login Page module by exploiting an alternate path or ch...

Jan 28, 2026
CVE-2026-2540
N/A

The Micca KE700 vehicle alarm system contains a cryptographic flaw that allows replay attacks. Attackers can capture and replay rolling codes to clone...

Feb 15, 2026
CVE-2025-10538
N/A

An authentication bypass vulnerability in LG Innotek LND7210 and LNV7210R cameras allows attackers to access camera information including user account...

Oct 1, 2025

About CWE-288 (CWE-288)

Our database tracks 236 CVEs classified as CWE-288, with 130 rated critical and 74 rated high severity. The average CVSS score for CWE-288 vulnerabilities is 8.7.

External reference: View CWE-288 on MITRE CWE →

Monitor CWE-288 Vulnerabilities

Get alerted when new CWE-288 CVEs affect your infrastructure.

Start Monitoring Free