CWE-288: CWE-288
Yearly Trend
Top Affected Vendors
All CWE-288 CVEs (236)
This vulnerability allows authenticated administrative users on Nokia Single RAN AirScale baseband systems to access all physical boards after a singl...
Jul 2, 2025This vulnerability allows local attackers to bypass authentication on Siemens SCALANCE LPE9403 devices with SINEMA Remote Connect Edge Client installe...
May 13, 2025This vulnerability allows attackers to bypass the physical button pairing requirement on 70mai Dash Cam 1S devices by directly connecting to the devic...
Mar 24, 2025An authentication bypass vulnerability in Trivision Camera NC227WF v5.8.0 allows attackers to retrieve administrator credentials in cleartext by sendi...
Feb 27, 2025This vulnerability allows authenticated users to bypass WebAuthn two-factor authentication in GitLab by manipulating session state. It affects GitLab ...
Dec 11, 2025This vulnerability allows physical attackers to reset the admin password on Elspec G5 devices by inserting a USB drive with a specific reset string. I...
Nov 6, 2025This vulnerability allows attackers to bypass Device OAuth flow protections in GitLab, enabling unauthorized authorization form submissions with minim...
May 9, 2025This CVE describes an authentication bypass vulnerability in FortiOS and FortiProxy that allows authenticated attackers to elevate privileges via mali...
Oct 2, 2025This CVE describes an authentication bypass vulnerability in Drupal's Microsoft Entra ID SSO Login module that allows attackers to access privileged f...
Feb 4, 2026This CVE describes an authentication bypass vulnerability in LibreOffice on macOS where the bundled Python interpreter inherits the main application's...
Dec 15, 2025A policy bypass vulnerability in Google Chrome extensions allows malicious extensions to leak cross-origin data. Attackers can exploit this by convinc...
Nov 10, 2025This vulnerability allows attackers to bypass Chrome's navigation restrictions by tricking users into installing a malicious extension. It affects all...
Nov 10, 2025IBM OpenPages with Watson versions 8.3 and 9.0 contain an improper authorization vulnerability in APIs that allows authenticated users to access sensi...
Aug 22, 2024This CVE describes an authentication bypass vulnerability in PruvaSoft Informatics Apinizer Management Console that allows attackers to access protect...
Jul 18, 2024This CVE describes a mitigation bypass vulnerability in the DOM: Core & HTML component of Mozilla products. It allows attackers to bypass security mit...
Nov 11, 2025Multiple authorization bypass vulnerabilities in TIM BPM Suite/TIM FLOW allow low-privileged users to access sensitive data and modify restricted cont...
Jan 9, 2026This vulnerability allows users with htaccess file access to bypass mod_userdir+suexec restrictions via the RequestHeader directive, potentially causi...
Dec 5, 2025This vulnerability allows attackers to bypass two-factor authentication (2FA) in Drupal's Email TFA module, potentially gaining unauthorized access to...
Nov 18, 2025This CVE describes a mitigation bypass vulnerability in the Web Compatibility: Tooling component of Firefox and Thunderbird. Attackers could potential...
Sep 16, 2025This vulnerability allows attackers to bypass the lock screen authentication on Reolink mobile apps by exploiting Android Debug Bridge (ADB) access. I...
Aug 22, 2025This vulnerability allows attackers to bypass authentication mechanisms in Drupal CKEditor 5 Premium Features, potentially gaining unauthorized access...
Jan 28, 2026The Petlibro Smart Pet Feeder Platform contains an information disclosure vulnerability that allows attackers to access private audio recordings of ot...
Jan 4, 2026An authentication bypass vulnerability in Zoom Rooms Clients allows unauthenticated attackers to access sensitive information via network access. This...
Oct 15, 2025This vulnerability allows unauthenticated attackers to access course progress data in Masteriyo LMS WordPress plugin without proper authentication. It...
May 19, 2025An authentication bypass vulnerability in Ivanti Endpoint Manager Mobile's API allows attackers to access protected resources without valid credential...
May 13, 2025This CVE describes a semicolon path injection vulnerability in Scoold's API endpoint that allows unauthenticated attackers to bypass authentication an...
Oct 29, 2024EC-CUBE contains an MFA bypass vulnerability that allows attackers with valid administrator credentials to circumvent two-factor authentication and ac...
Mar 5, 2026This vulnerability allows attackers to bypass multi-factor authentication in Drupal Enterprise MFA - TFA for Drupal by using an alternate path or chan...
Jun 26, 2025This CVE describes an authentication bypass vulnerability in the Drupal One Time Password module that allows attackers to bypass functionality by usin...
May 21, 2025This vulnerability allows attackers to bypass authentication by modifying bootloader arguments, gaining access to the file system and password hashes....
Jun 13, 2024This vulnerability allows Developer-role users in GitLab EE to make unauthorized modifications to protected Conan packages when they lack proper permi...
Feb 25, 2026This vulnerability allows attackers to use stored user credentials from the local database to gain unauthorized access to affected systems. It affects...
Oct 6, 2025This vulnerability allows authenticated IBM i users to bypass interface restrictions in Navigator for i by sending specially crafted requests. Attacke...
Dec 21, 2024This vulnerability allows attackers to bypass authentication in Drupal sites using the Disable Login Page module by exploiting an alternate path or ch...
Jan 28, 2026The Micca KE700 vehicle alarm system contains a cryptographic flaw that allows replay attacks. Attackers can capture and replay rolling codes to clone...
Feb 15, 2026An authentication bypass vulnerability in LG Innotek LND7210 and LNV7210R cameras allows attackers to access camera information including user account...
Oct 1, 2025About CWE-288 (CWE-288)
Our database tracks 236 CVEs classified as CWE-288, with 130 rated critical and 74 rated high severity. The average CVSS score for CWE-288 vulnerabilities is 8.7.
External reference: View CWE-288 on MITRE CWE →
Monitor CWE-288 Vulnerabilities
Get alerted when new CWE-288 CVEs affect your infrastructure.
Start Monitoring Free