CWE-288 · 656 записей
Authentication Bypass Using an Alternate Path or Channel
CVE этого класса
656 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2024-1709Готовый эксплойт | Authentication bypass using an alternate path or channelconnectwise · screenconnect · CWE-288 | Критическая10,0 | KEV | 100,0 % | 21 февр. 2024 г. |
99Срочно | CVE-2023-42793Готовый эксплойт | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possiblejetbrains · teamcity · CWE-288 | Критическая9,8 | KEV | 100,0 % | 19 сент. 2023 г. |
99Срочно | CVE-2024-27198Готовый эксплойт | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possiblejetbrains · teamcity · CWE-288 | Критическая9,8 | KEV | 99,9 % | 4 мар. 2024 г. |
98Срочно | CVE-2025-2747Готовый эксплойт | Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypasskentico · xperience · CWE-288 | Критическая9,8 | KEV | 97,2 % | 24 мар. 2025 г. |
98Срочно | CVE-2023-46747Готовый эксплойт | BIG-IP Configuration utility unauthenticated remote code execution vulnerabilityf5 · big-ip access policy manager · CWE-288 | Критическая9,8 | KEV | 96,5 % | 26 окт. 2023 г. |
97Срочно | CVE-2024-55591Готовый эксплойт | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and Fortifortinet · fortiproxy · CWE-288 | Критическая9,8 | KEV | 94,1 % | 14 янв. 2025 г. |
97Срочно | CVE-2020-10148Готовый эксплойт | SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commandssolarwinds · orion platform · CWE-288 | Критическая9,8 | KEV | 92,0 % | 29 дек. 2020 г. |
96Срочно | CVE-2026-23760Готовый эксплойт | SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset APIsmartertools · smartermail · CWE-288 | Критическая9,3 | KEV | 96,5 % | 22 янв. 2026 г. |
96Срочно | CVE-2026-20079Готовый эксплойт | Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerabilitycisco · secure firewall management center · CWE-288 | Критическая10,0 | KEV | 88,2 % | 4 мар. 2026 г. |
95Срочно | CVE-2026-24858Готовый эксплойт | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.fortinet · fortianalyzer · CWE-288 | Критическая9,8 | KEV | 85,8 % | 27 янв. 2026 г. |
91Срочно | CVE-2025-34026Готовый эксплойт | Versa Concerto Actuator Authentication Bypass Information Leakversa-networks · concerto · CWE-288 | Критическая9,2 | KEV | 81,9 % | 21 мая 2025 г. |
91Срочно | CVE-2025-2746Готовый эксплойт | Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypasskentico · xperience · CWE-288 | Критическая9,8 | KEV | 73,0 % | 24 мар. 2025 г. |
90Срочно | CVE-2025-4427Готовый эксплойт | Authentication Bypassivanti · endpoint manager mobile · CWE-288 | Высокая7,5 | KEV | 99,9 % | 13 мая 2025 г. |
86Срочно | CVE-2026-1603Готовый эксплойт | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific storedivanti · endpoint manager · CWE-288 | Высокая7,5 | KEV | 87,6 % | 10 февр. 2026 г. |
74На этой неделе | CVE-2023-20269Готовый эксплойт | A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTDcisco · adaptive security appliance software · CWE-288 | Критическая9,1 | KEV | 25,5 % | 6 сент. 2023 г. |
69На этой неделе | CVE-2026-19490Готовый эксплойт | NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490citrix · netscaler application delivery controller · CWE-288 | Критическая9,3 | KEV | 7,0 % | 19 авг. 2026 г. |
66На этой неделе | CVE-2026-18577Готовый эксплойт | Incomplete patch leads to administrative account takeovern-able · n-central · CWE-288 | Высокая8,2 | KEV | 14,6 % | 2 авг. 2026 г. |
64На этой неделе | CVE-2024-10924Готовый эксплойт | Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypassreally-simple-plugins · really simple security · CWE-288 | Критическая9,8 | — | 82,2 % | 15 нояб. 2024 г. |
64На этой неделе | CVE-2026-18556Готовый эксплойт | Unauthenticated administrative account takeovern-able · n-central · CWE-288 | Высокая8,2 | KEV | 7,9 % | 1 авг. 2026 г. |
64На этой неделе | CVE-2025-24472Готовый эксплойт | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.fortinet · fortiproxy · CWE-288 | Высокая8,1 | KEV | 7,2 % | 11 февр. 2025 г. |
63На этой неделе | CVE-2024-56325Proof of concept | Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not requiredapache · pinot · CWE-288 | Критическая9,8 | — | 80,2 % | 1 апр. 2025 г. |
59В плане | CVE-2023-2732Proof of concept | MStore API <= 3.9.2 - Authentication Bypassinspireui · mstore api · CWE-288 | Критическая9,8 | — | 67,5 % | 24 мая 2023 г. |
57В плане | CVE-2022-35869Эксплойта нет | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022inductiveautomation · ignition · CWE-288 | Критическая9,8 | — | 60,3 % | 25 июл. 2022 г. |
55В плане | CVE-2024-23917Proof of concept | In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possiblejetbrains · teamcity · CWE-288 | Критическая9,8 | — | 54,0 % | 6 февр. 2024 г. |
55В плане | CVE-2026-10523Proof of concept | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthentivanti · standalone sentry · CWE-288 | Критическая9,8 | — | 53,1 % | 9 июн. 2026 г. |
- CVE-2024-1709100Срочно
Authentication bypass using an alternate path or channel
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %connectwise · screenconnect21 февр. 2024 г.
- CVE-2023-4279399Срочно
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %jetbrains · teamcity19 сент. 2023 г.
- CVE-2024-2719899Срочно
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %jetbrains · teamcity4 мар. 2024 г.
- CVE-2025-274798Срочно
Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %kentico · xperience24 мар. 2025 г.
- CVE-2023-4674798Срочно
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %f5 · big-ip access policy manager26 окт. 2023 г.
- CVE-2024-5559197Срочно
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and Forti
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %fortinet · fortiproxy14 янв. 2025 г.
- CVE-2020-1014897Срочно
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %solarwinds · orion platform29 дек. 2020 г.
- CVE-2026-2376096Срочно
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 97 %smartertools · smartermail22 янв. 2026 г.
- CVE-2026-2007996Срочно
Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 88 %cisco · secure firewall management center4 мар. 2026 г.
- CVE-2026-2485895Срочно
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %fortinet · fortianalyzer27 янв. 2026 г.
- CVE-2025-3402691Срочно
Versa Concerto Actuator Authentication Bypass Information Leak
КритическаяCVSS 9,2KEVГотовый эксплойтEPSS 82 %versa-networks · concerto21 мая 2025 г.
- CVE-2025-274691Срочно
Kentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 73 %kentico · xperience24 мар. 2025 г.
- CVE-2025-442790Срочно
Authentication Bypass
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager mobile13 мая 2025 г.
- CVE-2026-160386Срочно
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 88 %ivanti · endpoint manager10 февр. 2026 г.
- CVE-2023-2026974На этой неделе
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 25 %cisco · adaptive security appliance software6 сент. 2023 г.
- CVE-2026-1949069На этой неделе
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 7 %citrix · netscaler application delivery controller19 авг. 2026 г.
- CVE-2026-1857766На этой неделе
Incomplete patch leads to administrative account takeover
ВысокаяCVSS 8,2KEVГотовый эксплойтEPSS 15 %n-able · n-central2 авг. 2026 г.
- CVE-2024-1092464На этой неделе
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %really-simple-plugins · really simple security15 нояб. 2024 г.
- CVE-2026-1855664На этой неделе
Unauthenticated administrative account takeover
ВысокаяCVSS 8,2KEVГотовый эксплойтEPSS 8 %n-able · n-central1 авг. 2026 г.
- CVE-2025-2447264На этой неделе
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 7 %fortinet · fortiproxy11 февр. 2025 г.
- CVE-2024-5632563На этой неделе
Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required
КритическаяCVSS 9,8Proof of conceptEPSS 80 %apache · pinot1 апр. 2025 г.
- CVE-2023-273259В плане
MStore API <= 3.9.2 - Authentication Bypass
КритическаяCVSS 9,8Proof of conceptEPSS 68 %inspireui · mstore api24 мая 2023 г.
- CVE-2022-3586957В плане
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022
КритическаяCVSS 9,8Эксплойта нетEPSS 60 %inductiveautomation · ignition25 июл. 2022 г.
- CVE-2024-2391755В плане
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
КритическаяCVSS 9,8Proof of conceptEPSS 54 %jetbrains · teamcity6 февр. 2024 г.
- CVE-2026-1052355В плане
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthent
КритическаяCVSS 9,8Proof of conceptEPSS 53 %ivanti · standalone sentry9 июн. 2026 г.