CWE-302: CWE-302

18
Total CVEs
5
Critical
8
High
7.7
Avg CVSS

Yearly Trend

2026
1
2025
7
2024
8
2023
1
2022
1

Top Affected Vendors

1 Microsoft 2
2 Gitlab 1
3 Apache 1
4 Cisco 1
5 Zitadel 1
6 Apereo 1
7 Apexsoftcell 1
8 Yokogawa 1

All CWE-302 CVEs (18)

CVE-2025-29813
10.0

CVE-2025-29813 is an authentication bypass vulnerability in Azure DevOps that allows attackers to spoof identity claims and gain unauthorized access. ...

May 8, 2025
CVE-2024-56404
9.9

An insecure direct object reference (IDOR) vulnerability in One Identity Identity Manager 9.x before version 9.3 allows authenticated attackers to esc...

Jan 24, 2025
CVE-2024-43441
9.8

This vulnerability allows attackers to bypass authentication in Apache HugeGraph-Server by manipulating data assumed to be immutable. It affects all u...

Dec 24, 2024
CVE-2023-4612
9.8

CVE-2023-4612 is an authentication bypass vulnerability in Apereo CAS that allows attackers to circumvent Multi-Factor Authentication by manipulating ...

Nov 9, 2023
CVE-2025-47158
9.0

This authentication bypass vulnerability in Azure DevOps allows attackers to gain unauthorized access by manipulating data assumed to be immutable. At...

Jul 18, 2025
CVE-2024-12838
8.8

CVE-2024-12838 is an authentication bypass vulnerability in CGFIDO's passwordless login mechanism that allows regular users to impersonate any other u...

Dec 31, 2024
CVE-2022-22729
8.8

CVE-2022-22729 is an authentication bypass vulnerability in Yokogawa's CAMS for HIS Server that allows attackers to send specially crafted packets to ...

Mar 11, 2022
CVE-2025-8855
8.1

This vulnerability in Optimus Software Brokerage Automation allows attackers to bypass authentication and authorization controls through multiple weak...

Nov 14, 2025
CVE-2025-24876
8.1

CVE-2025-24876 is an authentication bypass vulnerability in SAP Approuter Node.js package that allows attackers to steal user sessions during authoriz...

Feb 11, 2025
CVE-2024-3741
7.5

Electrolink transmitters have an authentication bypass vulnerability where attackers can gain full system access by setting any value except 'NO' in t...

Apr 18, 2024
CVE-2024-22179
7.5

This vulnerability allows unauthenticated attackers to bypass authentication by manipulating parameters to set credentials to blank, gaining access to...

Apr 18, 2024
CVE-2024-45370
7.3

An authentication bypass vulnerability in Socomec Easy Config System 2.6.1.0 allows attackers to gain unauthorized access by modifying local database ...

Dec 1, 2025
CVE-2024-4024
7.3

This vulnerability allows an attacker with Bitbucket credentials to hijack GitLab accounts linked to other users' Bitbucket accounts when Bitbucket is...

Apr 25, 2024
CVE-2024-8475
6.5

This vulnerability allows attackers to bypass authentication in WiFiBurada by manipulating user-controlled variables that were assumed to be immutable...

Dec 17, 2024
CVE-2024-47086
6.5

This vulnerability allows authenticated attackers to bypass OTP verification for other user accounts in Apex Softcell LD DP Back Office by manipulatin...

Sep 19, 2024
CVE-2024-3462
5.4

Ant Media Server Community Edition's default configuration has improper HTTP header-based authorization, allowing unauthorized users to access non-adm...

May 14, 2024
CVE-2026-27840
4.3

ZITADEL identity management platform versions 2.31.0 through 3.4.6 and 4.0.0 through 4.10.0 have a token validation flaw where truncated OIDC access t...

Feb 26, 2026
CVE-2025-20285
4.1

This vulnerability allows authenticated remote attackers with administrative credentials to bypass IP access restrictions on Cisco ISE and ISE-PIC dev...

Jul 16, 2025

About CWE-302 (CWE-302)

Our database tracks 18 CVEs classified as CWE-302, with 5 rated critical and 8 rated high severity. The average CVSS score for CWE-302 vulnerabilities is 7.7.

External reference: View CWE-302 on MITRE CWE →

Monitor CWE-302 Vulnerabilities

Get alerted when new CWE-302 CVEs affect your infrastructure.

Start Monitoring Free