CWE-288 · 656 records
Authentication Bypass Using an Alternate Path or Channel
CVEs in this class
656 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2024-1709Weaponized | Authentication bypass using an alternate path or channelconnectwise · screenconnect · CWE-288 | Critical10.0 | KEV | 100.0% | Feb 21, 2024 |
99Now | CVE-2023-42793Weaponized | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possiblejetbrains · teamcity · CWE-288 | Critical9.8 | KEV | 100.0% | Sep 19, 2023 |
99Now | CVE-2024-27198Weaponized | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possiblejetbrains · teamcity · CWE-288 | Critical9.8 | KEV | 99.9% | Mar 4, 2024 |
98Now | CVE-2025-2747Weaponized | Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypasskentico · xperience · CWE-288 | Critical9.8 | KEV | 97.2% | Mar 24, 2025 |
98Now | CVE-2023-46747Weaponized | BIG-IP Configuration utility unauthenticated remote code execution vulnerabilityf5 · big-ip access policy manager · CWE-288 | Critical9.8 | KEV | 96.5% | Oct 26, 2023 |
97Now | CVE-2024-55591Weaponized | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and Fortifortinet · fortiproxy · CWE-288 | Critical9.8 | KEV | 94.1% | Jan 14, 2025 |
97Now | CVE-2020-10148Weaponized | SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commandssolarwinds · orion platform · CWE-288 | Critical9.8 | KEV | 92.0% | Dec 29, 2020 |
96Now | CVE-2026-23760Weaponized | SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset APIsmartertools · smartermail · CWE-288 | Critical9.3 | KEV | 96.5% | Jan 22, 2026 |
96Now | CVE-2026-20079Weaponized | Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerabilitycisco · secure firewall management center · CWE-288 | Critical10.0 | KEV | 88.2% | Mar 4, 2026 |
95Now | CVE-2026-24858Weaponized | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.fortinet · fortianalyzer · CWE-288 | Critical9.8 | KEV | 85.8% | Jan 27, 2026 |
91Now | CVE-2025-34026Weaponized | Versa Concerto Actuator Authentication Bypass Information Leakversa-networks · concerto · CWE-288 | Critical9.2 | KEV | 81.9% | May 21, 2025 |
91Now | CVE-2025-2746Weaponized | Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypasskentico · xperience · CWE-288 | Critical9.8 | KEV | 73.0% | Mar 24, 2025 |
90Now | CVE-2025-4427Weaponized | Authentication Bypassivanti · endpoint manager mobile · CWE-288 | High7.5 | KEV | 99.9% | May 13, 2025 |
86Now | CVE-2026-1603Weaponized | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific storedivanti · endpoint manager · CWE-288 | High7.5 | KEV | 87.6% | Feb 10, 2026 |
74This week | CVE-2023-20269Weaponized | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTDcisco · adaptive security appliance software · CWE-288 | Critical9.1 | KEV | 25.5% | Sep 6, 2023 |
69This week | CVE-2026-19490Weaponized | NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490citrix · netscaler application delivery controller · CWE-288 | Critical9.3 | KEV | 7.0% | Aug 19, 2026 |
66This week | CVE-2026-18577Weaponized | Incomplete patch leads to administrative account takeovern-able · n-central · CWE-288 | High8.2 | KEV | 14.6% | Aug 2, 2026 |
64This week | CVE-2024-10924Weaponized | Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypassreally-simple-plugins · really simple security · CWE-288 | Critical9.8 | — | 82.2% | Nov 15, 2024 |
64This week | CVE-2026-18556Weaponized | Unauthenticated administrative account takeovern-able · n-central · CWE-288 | High8.2 | KEV | 7.9% | Aug 1, 2026 |
64This week | CVE-2025-24472Weaponized | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.fortinet · fortiproxy · CWE-288 | High8.1 | KEV | 7.2% | Feb 11, 2025 |
63This week | CVE-2024-56325Proof of concept | Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not requiredapache · pinot · CWE-288 | Critical9.8 | — | 80.2% | Apr 1, 2025 |
59Plan | CVE-2023-2732Proof of concept | MStore API <= 3.9.2 - Authentication Bypassinspireui · mstore api · CWE-288 | Critical9.8 | — | 67.5% | May 24, 2023 |
57Plan | CVE-2022-35869No exploit | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022inductiveautomation · ignition · CWE-288 | Critical9.8 | — | 60.3% | Jul 25, 2022 |
55Plan | CVE-2024-23917Proof of concept | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possiblejetbrains · teamcity · CWE-288 | Critical9.8 | — | 54.0% | Feb 6, 2024 |
55Plan | CVE-2026-10523Proof of concept | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthentivanti · standalone sentry · CWE-288 | Critical9.8 | — | 53.1% | Jun 9, 2026 |
- CVE-2024-1709100Now
Authentication bypass using an alternate path or channel
CriticalCVSS 10.0KEVWeaponizedEPSS 100%connectwise · screenconnectFeb 21, 2024
- CVE-2023-4279399Now
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
CriticalCVSS 9.8KEVWeaponizedEPSS 100%jetbrains · teamcitySep 19, 2023
- CVE-2024-2719899Now
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
CriticalCVSS 9.8KEVWeaponizedEPSS 100%jetbrains · teamcityMar 4, 2024
- CVE-2025-274798Now
Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
CriticalCVSS 9.8KEVWeaponizedEPSS 97%kentico · xperienceMar 24, 2025
- CVE-2023-4674798Now
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 97%f5 · big-ip access policy managerOct 26, 2023
- CVE-2024-5559197Now
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and Forti
CriticalCVSS 9.8KEVWeaponizedEPSS 94%fortinet · fortiproxyJan 14, 2025
- CVE-2020-1014897Now
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
CriticalCVSS 9.8KEVWeaponizedEPSS 92%solarwinds · orion platformDec 29, 2020
- CVE-2026-2376096Now
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
CriticalCVSS 9.3KEVWeaponizedEPSS 97%smartertools · smartermailJan 22, 2026
- CVE-2026-2007996Now
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
CriticalCVSS 10.0KEVWeaponizedEPSS 88%cisco · secure firewall management centerMar 4, 2026
- CVE-2026-2485895Now
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.
CriticalCVSS 9.8KEVWeaponizedEPSS 86%fortinet · fortianalyzerJan 27, 2026
- CVE-2025-3402691Now
Versa Concerto Actuator Authentication Bypass Information Leak
CriticalCVSS 9.2KEVWeaponizedEPSS 82%versa-networks · concertoMay 21, 2025
- CVE-2025-274691Now
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
CriticalCVSS 9.8KEVWeaponizedEPSS 73%kentico · xperienceMar 24, 2025
- CVE-2025-442790Now
Authentication Bypass
HighCVSS 7.5KEVWeaponizedEPSS 100%ivanti · endpoint manager mobileMay 13, 2025
- CVE-2026-160386Now
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored
HighCVSS 7.5KEVWeaponizedEPSS 88%ivanti · endpoint managerFeb 10, 2026
- CVE-2023-2026974This week
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD
CriticalCVSS 9.1KEVWeaponizedEPSS 25%cisco · adaptive security appliance softwareSep 6, 2023
- CVE-2026-1949069This week
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
CriticalCVSS 9.3KEVWeaponizedEPSS 7%citrix · netscaler application delivery controllerAug 19, 2026
- CVE-2026-1857766This week
Incomplete patch leads to administrative account takeover
HighCVSS 8.2KEVWeaponizedEPSS 15%n-able · n-centralAug 2, 2026
- CVE-2024-1092464This week
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
CriticalCVSS 9.8WeaponizedEPSS 82%really-simple-plugins · really simple securityNov 15, 2024
- CVE-2026-1855664This week
Unauthenticated administrative account takeover
HighCVSS 8.2KEVWeaponizedEPSS 8%n-able · n-centralAug 1, 2026
- CVE-2025-2447264This week
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.
HighCVSS 8.1KEVWeaponizedEPSS 7%fortinet · fortiproxyFeb 11, 2025
- CVE-2024-5632563This week
Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required
CriticalCVSS 9.8Proof of conceptEPSS 80%apache · pinotApr 1, 2025
- CVE-2023-273259Plan
MStore API <= 3.9.2 - Authentication Bypass
CriticalCVSS 9.8Proof of conceptEPSS 68%inspireui · mstore apiMay 24, 2023
- CVE-2022-3586957Plan
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022
CriticalCVSS 9.8No exploitEPSS 60%inductiveautomation · ignitionJul 25, 2022
- CVE-2024-2391755Plan
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
CriticalCVSS 9.8Proof of conceptEPSS 54%jetbrains · teamcityFeb 6, 2024
- CVE-2026-1052355Plan
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthent
CriticalCVSS 9.8Proof of conceptEPSS 53%ivanti · standalone sentryJun 9, 2026