CWE-302: CWE-302
Yearly Trend
Top Affected Vendors
All CWE-302 CVEs (18)
CVE-2025-29813 is an authentication bypass vulnerability in Azure DevOps that allows attackers to spoof identity claims and gain unauthorized access. ...
May 8, 2025An insecure direct object reference (IDOR) vulnerability in One Identity Identity Manager 9.x before version 9.3 allows authenticated attackers to esc...
Jan 24, 2025This vulnerability allows attackers to bypass authentication in Apache HugeGraph-Server by manipulating data assumed to be immutable. It affects all u...
Dec 24, 2024CVE-2023-4612 is an authentication bypass vulnerability in Apereo CAS that allows attackers to circumvent Multi-Factor Authentication by manipulating ...
Nov 9, 2023This authentication bypass vulnerability in Azure DevOps allows attackers to gain unauthorized access by manipulating data assumed to be immutable. At...
Jul 18, 2025CVE-2024-12838 is an authentication bypass vulnerability in CGFIDO's passwordless login mechanism that allows regular users to impersonate any other u...
Dec 31, 2024CVE-2022-22729 is an authentication bypass vulnerability in Yokogawa's CAMS for HIS Server that allows attackers to send specially crafted packets to ...
Mar 11, 2022This vulnerability in Optimus Software Brokerage Automation allows attackers to bypass authentication and authorization controls through multiple weak...
Nov 14, 2025CVE-2025-24876 is an authentication bypass vulnerability in SAP Approuter Node.js package that allows attackers to steal user sessions during authoriz...
Feb 11, 2025Electrolink transmitters have an authentication bypass vulnerability where attackers can gain full system access by setting any value except 'NO' in t...
Apr 18, 2024This vulnerability allows unauthenticated attackers to bypass authentication by manipulating parameters to set credentials to blank, gaining access to...
Apr 18, 2024An authentication bypass vulnerability in Socomec Easy Config System 2.6.1.0 allows attackers to gain unauthorized access by modifying local database ...
Dec 1, 2025This vulnerability allows an attacker with Bitbucket credentials to hijack GitLab accounts linked to other users' Bitbucket accounts when Bitbucket is...
Apr 25, 2024This vulnerability allows attackers to bypass authentication in WiFiBurada by manipulating user-controlled variables that were assumed to be immutable...
Dec 17, 2024This vulnerability allows authenticated attackers to bypass OTP verification for other user accounts in Apex Softcell LD DP Back Office by manipulatin...
Sep 19, 2024Ant Media Server Community Edition's default configuration has improper HTTP header-based authorization, allowing unauthorized users to access non-adm...
May 14, 2024ZITADEL identity management platform versions 2.31.0 through 3.4.6 and 4.0.0 through 4.10.0 have a token validation flaw where truncated OIDC access t...
Feb 26, 2026This vulnerability allows authenticated remote attackers with administrative credentials to bypass IP access restrictions on Cisco ISE and ISE-PIC dev...
Jul 16, 2025About CWE-302 (CWE-302)
Our database tracks 18 CVEs classified as CWE-302, with 5 rated critical and 8 rated high severity. The average CVSS score for CWE-302 vulnerabilities is 7.7.
External reference: View CWE-302 on MITRE CWE →
Monitor CWE-302 Vulnerabilities
Get alerted when new CWE-302 CVEs affect your infrastructure.
Start Monitoring Free