Skip to content
Noroxi

CWE-289 · 42 records

Authentication Bypass by Alternate Name

CVEs in this class

42 records

  • DataEase has an unauthorized vulnerability

    CriticalCVSS 9.3Proof of conceptEPSS 44%

    dataease · dataeaseJan 10, 2025

  • Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability

    CriticalCVSS 9.8No exploitEPSS 18%

    cisco · enterprise nfv infrastructure softwareSep 1, 2021

  • CVE-2023-1803
    39Monitor

    Authentication Bypass in Redline Router

    CriticalCVSS 9.8No exploitEPSS 1%

    redline · router firmwareApr 14, 2023

  • CVE-2026-8457
    39Monitor

    WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT

    CriticalCVSS 9.8No exploitEPSS 1%

    wpweb · woocommerce - social loginAug 1, 2026

  • CVE-2026-9701
    39Monitor

    Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation

    CriticalCVSS 9.8No exploitEPSS 0%

    joe007 · eventerJul 8, 2026

  • Elated Membership <= 1.2 - Authentication Bypass via Social Login

    CriticalCVSS 9.8No exploitEPSS 0%

    elated themes · elated membershipDec 9, 2025

  • MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token

    CriticalCVSS 9.8No exploitEPSS 0%

    tangiblewp · myhome coreAug 30, 2026

  • Apache Tomcat: Bypass of security constraints for WebSocket endpoints

    CriticalCVSS 9.8No exploitEPSS 0%

    apache software foundation · apache tomcatSep 23, 2026

  • Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is r

    CriticalCVSS 9.6No exploitEPSS 0%

    unraid · unraidMar 31, 2025

  • A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relativ

    CriticalCVSS 9.1Proof of conceptEPSS 2%

    nodejs · node.jsJan 20, 2026

  • This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.69

    HighCVSS 8.8No exploitEPSS 3%

    netgain-systems · enterprise managerJan 22, 2018

  • Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator

    CriticalCVSS 9.1No exploitEPSS 1%

    apache · cxfJun 12, 2026

  • A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevat

    HighCVSS 8.8No exploitEPSS 1%

    cisco · starosMay 9, 2023

  • OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channels

    HighCVSS 8.3No exploitEPSS 1%

    openclaw · openclawMar 19, 2026

  • HedgeDoc API allows to hide existing notes

    HighCVSS 8.2No exploitEPSS 1%

    hedgedoc · hedgedocAug 4, 2023

  • Apache Shiro: Authentication bypass in Guice-Web integration

    HighCVSS 8.2No exploitEPSS 1%

    apache software foundation · apache shiroJun 25, 2026

  • Soft Serve has Critical Authentication Bypass

    HighCVSS 8.1No exploitEPSS 1%

    charm · soft serveJan 22, 2026

  • Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login

    HighCVSS 8.1No exploitEPSS 0%

    radiustheme · classified listing - mobile number verificationAug 26, 2026

  • Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access

    HighCVSS 8.1No exploitEPSS 0%

    ibm · verify identity accessSep 15, 2026

  • (conda) Constructor: Excessive permissions during and after installation

    HighCVSS 7.8No exploitEPSS 0%

    conda · constructorNov 7, 2025

  • Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation

    HighCVSS 7.5No exploitEPSS 1%

    sustainsys · saml2Sep 19, 2023

  • CVE-2023-3263
    30Monitor

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the

    HighCVSS 7.5No exploitEPSS 1%

    dataprobe · iboot-pdu4a-c10 firmwareAug 14, 2023

  • IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    ibm · websphere application serverJul 30, 2026

  • CVE-2024-2098
    30Monitor

    Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary

    HighCVSS 7.5No exploitEPSS 0%

    w3eden · download managerJun 13, 2024

  • CVE-2025-41248: Spring Security authorization bypass for method security annotations on parameterized types

    HighCVSS 7.5No exploitEPSS 0%

    vmware · spring securitySep 16, 2025

All vulnerability classes