Skip to content
Noroxi

CWE-288 · 656 records

Authentication Bypass Using an Alternate Path or Channel

CVEs in this class

656 records

  • Authentication bypass using an alternate path or channel

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    connectwise · screenconnectFeb 21, 2024

  • In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    jetbrains · teamcitySep 19, 2023

  • In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    jetbrains · teamcityMar 4, 2024

  • Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    kentico · xperienceMar 24, 2025

  • BIG-IP Configuration utility unauthenticated remote code execution vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    f5 · big-ip access policy managerOct 26, 2023

  • An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and Forti

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    fortinet · fortiproxyJan 14, 2025

  • SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    solarwinds · orion platformDec 29, 2020

  • SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API

    CriticalCVSS 9.3KEVWeaponizedEPSS 97%

    smartertools · smartermailJan 22, 2026

  • Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability

    CriticalCVSS 10.0KEVWeaponizedEPSS 88%

    cisco · secure firewall management centerMar 4, 2026

  • An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.

    CriticalCVSS 9.8KEVWeaponizedEPSS 86%

    fortinet · fortianalyzerJan 27, 2026

  • Versa Concerto Actuator Authentication Bypass Information Leak

    CriticalCVSS 9.2KEVWeaponizedEPSS 82%

    versa-networks · concertoMay 21, 2025

  • Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass

    CriticalCVSS 9.8KEVWeaponizedEPSS 73%

    kentico · xperienceMar 24, 2025

  • Authentication Bypass

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    ivanti · endpoint manager mobileMay 13, 2025

  • An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored

    HighCVSS 7.5KEVWeaponizedEPSS 88%

    ivanti · endpoint managerFeb 10, 2026

  • CVE-2023-20269
    74This week

    A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD

    CriticalCVSS 9.1KEVWeaponizedEPSS 25%

    cisco · adaptive security appliance softwareSep 6, 2023

  • CVE-2026-19490
    69This week

    NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490

    CriticalCVSS 9.3KEVWeaponizedEPSS 7%

    citrix · netscaler application delivery controllerAug 19, 2026

  • CVE-2026-18577
    66This week

    Incomplete patch leads to administrative account takeover

    HighCVSS 8.2KEVWeaponizedEPSS 15%

    n-able · n-centralAug 2, 2026

  • CVE-2024-10924
    64This week

    Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass

    CriticalCVSS 9.8WeaponizedEPSS 82%

    really-simple-plugins · really simple securityNov 15, 2024

  • CVE-2026-18556
    64This week

    Unauthenticated administrative account takeover

    HighCVSS 8.2KEVWeaponizedEPSS 8%

    n-able · n-centralAug 1, 2026

  • CVE-2025-24472
    64This week

    An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.

    HighCVSS 8.1KEVWeaponizedEPSS 7%

    fortinet · fortiproxyFeb 11, 2025

  • CVE-2024-56325
    63This week

    Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required

    CriticalCVSS 9.8Proof of conceptEPSS 80%

    apache · pinotApr 1, 2025

  • MStore API <= 3.9.2 - Authentication Bypass

    CriticalCVSS 9.8Proof of conceptEPSS 68%

    inspireui · mstore apiMay 24, 2023

  • This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022

    CriticalCVSS 9.8No exploitEPSS 60%

    inductiveautomation · ignitionJul 25, 2022

  • In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

    CriticalCVSS 9.8Proof of conceptEPSS 54%

    jetbrains · teamcityFeb 6, 2024

  • An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthent

    CriticalCVSS 9.8Proof of conceptEPSS 53%

    ivanti · standalone sentryJun 9, 2026

All vulnerability classes