CWE-289 · 42 записей
Authentication Bypass by Alternate Name
CVE этого класса
42 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
50В плане | CVE-2024-56511Proof of concept | DataEase has an unauthorized vulnerabilitydataease · dataease · CWE-289 | Критическая9,3 | — | 44,5 % | 10 янв. 2025 г. |
44В плане | CVE-2021-34746Эксплойта нет | Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerabilitycisco · enterprise nfv infrastructure software · CWE-289 | Критическая9,8 | — | 17,7 % | 1 сент. 2021 г. |
39Наблюдать | CVE-2023-1803Эксплойта нет | Authentication Bypass in Redline Routerredline · router firmware · CWE-289 | Критическая9,8 | — | 0,8 % | 14 апр. 2023 г. |
39Наблюдать | CVE-2026-8457Эксплойта нет | WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWTwpweb · woocommerce - social login · CWE-289 | Критическая9,8 | — | 0,7 % | 1 авг. 2026 г. |
39Наблюдать | CVE-2026-9701Эксплойта нет | Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalationjoe007 · eventer · CWE-289 | Критическая9,8 | — | 0,5 % | 8 июл. 2026 г. |
39Наблюдать | CVE-2025-13613Эксплойта нет | Elated Membership <= 1.2 - Authentication Bypass via Social Loginelated themes · elated membership · CWE-289 | Критическая9,8 | — | 0,5 % | 9 дек. 2025 г. |
39Наблюдать | CVE-2026-15980Эксплойта нет | MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Tokentangiblewp · myhome core · CWE-289 | Критическая9,8 | — | 0,5 % | 30 авг. 2026 г. |
39Наблюдать | CVE-2026-76183Эксплойта нет | Apache Tomcat: Bypass of security constraints for WebSocket endpointsapache software foundation · apache tomcat · CWE-289 | Критическая9,8 | — | 0,4 % | 23 сент. 2026 г. |
38Наблюдать | CVE-2025-29266Эксплойта нет | Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is runraid · unraid · CWE-289 | Критическая9,6 | — | 0,4 % | 31 мар. 2025 г. |
37Наблюдать | CVE-2025-55130Proof of concept | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relativnodejs · node.js · CWE-289 | Критическая9,1 | — | 1,7 % | 20 янв. 2026 г. |
36Наблюдать | CVE-2017-16590Эксплойта нет | This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.69netgain-systems · enterprise manager · CWE-289 | Высокая8,8 | — | 3,3 % | 22 янв. 2018 г. |
36Наблюдать | CVE-2026-50627Эксплойта нет | Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validatorapache · cxf · CWE-289 | Критическая9,1 | — | 0,8 % | 12 июн. 2026 г. |
35Наблюдать | CVE-2023-20046Эксплойта нет | A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevatcisco · staros · CWE-289 | Высокая8,8 | — | 0,9 % | 9 мая 2023 г. |
33Наблюдать | CVE-2026-32036Эксплойта нет | OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channelsopenclaw · openclaw · CWE-289 | Высокая8,3 | — | 0,7 % | 19 мар. 2026 г. |
32Наблюдать | CVE-2023-38487Эксплойта нет | HedgeDoc API allows to hide existing noteshedgedoc · hedgedoc · CWE-289 | Высокая8,2 | — | 0,8 % | 4 авг. 2023 г. |
32Наблюдать | CVE-2026-56091Эксплойта нет | Apache Shiro: Authentication bypass in Guice-Web integrationapache software foundation · apache shiro · CWE-289 | Высокая8,2 | — | 0,7 % | 25 июн. 2026 г. |
32Наблюдать | CVE-2026-24058Эксплойта нет | Soft Serve has Critical Authentication Bypasscharm · soft serve · CWE-289 | Высокая8,1 | — | 0,6 % | 22 янв. 2026 г. |
32Наблюдать | CVE-2026-15985Эксплойта нет | Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Loginradiustheme · classified listing - mobile number verification · CWE-289 | Высокая8,1 | — | 0,3 % | 26 авг. 2026 г. |
32Наблюдать | CVE-2026-12101Эксплойта нет | Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Accessibm · verify identity access · CWE-289 | Высокая8,1 | — | 0,3 % | 15 сент. 2026 г. |
31Наблюдать | CVE-2025-64343Эксплойта нет | (conda) Constructor: Excessive permissions during and after installationconda · constructor · CWE-289 | Высокая7,8 | — | 0,1 % | 7 нояб. 2025 г. |
30Наблюдать | CVE-2023-41890Эксплойта нет | Sustainsys.Saml2 Insufficient Identity Provider Issuer Validationsustainsys · saml2 · CWE-289 | Высокая7,5 | — | 0,8 % | 19 сент. 2023 г. |
30Наблюдать | CVE-2023-3263Эксплойта нет | The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the dataprobe · iboot-pdu4a-c10 firmware · CWE-289 | Высокая7,5 | — | 0,7 % | 14 авг. 2023 г. |
30Наблюдать | CVE-2026-10842Эксплойта нет | IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerabilityibm · websphere application server · CWE-289 | Высокая7,5 | — | 0,5 % | 30 июл. 2026 г. |
30Наблюдать | CVE-2024-2098Эксплойта нет | Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibraryw3eden · download manager · CWE-289 | Высокая7,5 | — | 0,5 % | 13 июн. 2024 г. |
30Наблюдать | CVE-2025-41248Эксплойта нет | CVE-2025-41248: Spring Security authorization bypass for method security annotations on parameterized typesvmware · spring security · CWE-289 | Высокая7,5 | — | 0,4 % | 16 сент. 2025 г. |
- CVE-2024-5651150В плане
DataEase has an unauthorized vulnerability
КритическаяCVSS 9,3Proof of conceptEPSS 44 %dataease · dataease10 янв. 2025 г.
- CVE-2021-3474644В плане
Cisco Enterprise NFV Infrastructure Software Authentication Bypass Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %cisco · enterprise nfv infrastructure software1 сент. 2021 г.
- CVE-2023-180339Наблюдать
Authentication Bypass in Redline Router
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redline · router firmware14 апр. 2023 г.
- CVE-2026-845739Наблюдать
WooCommerce - Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wpweb · woocommerce - social login1 авг. 2026 г.
- CVE-2026-970139Наблюдать
Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %joe007 · eventer8 июл. 2026 г.
- CVE-2025-1361339Наблюдать
Elated Membership <= 1.2 - Authentication Bypass via Social Login
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %elated themes · elated membership9 дек. 2025 г.
- CVE-2026-1598039Наблюдать
MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %tangiblewp · myhome core30 авг. 2026 г.
- CVE-2026-7618339Наблюдать
Apache Tomcat: Bypass of security constraints for WebSocket endpoints
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %apache software foundation · apache tomcat23 сент. 2026 г.
- CVE-2025-2926638Наблюдать
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is r
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %unraid · unraid31 мар. 2025 г.
- CVE-2025-5513037Наблюдать
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relativ
КритическаяCVSS 9,1Proof of conceptEPSS 2 %nodejs · node.js20 янв. 2026 г.
- CVE-2017-1659036Наблюдать
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of NetGain Systems Enterprise Manager 7.2.69
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %netgain-systems · enterprise manager22 янв. 2018 г.
- CVE-2026-5062736Наблюдать
Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %apache · cxf12 июн. 2026 г.
- CVE-2023-2004635Наблюдать
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevat
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cisco · staros9 мая 2023 г.
- CVE-2026-3203633Наблюдать
OpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channels
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %openclaw · openclaw19 мар. 2026 г.
- CVE-2023-3848732Наблюдать
HedgeDoc API allows to hide existing notes
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %hedgedoc · hedgedoc4 авг. 2023 г.
- CVE-2026-5609132Наблюдать
Apache Shiro: Authentication bypass in Guice-Web integration
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %apache software foundation · apache shiro25 июн. 2026 г.
- CVE-2026-2405832Наблюдать
Soft Serve has Critical Authentication Bypass
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %charm · soft serve22 янв. 2026 г.
- CVE-2026-1598532Наблюдать
Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %radiustheme · classified listing - mobile number verification26 авг. 2026 г.
- CVE-2026-1210132Наблюдать
Security vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify Access
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %ibm · verify identity access15 сент. 2026 г.
- CVE-2025-6434331Наблюдать
(conda) Constructor: Excessive permissions during and after installation
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %conda · constructor7 нояб. 2025 г.
- CVE-2023-4189030Наблюдать
Sustainsys.Saml2 Insufficient Identity Provider Issuer Validation
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sustainsys · saml219 сент. 2023 г.
- CVE-2023-326330Наблюдать
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dataprobe · iboot-pdu4a-c10 firmware14 авг. 2023 г.
- CVE-2026-1084230Наблюдать
IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ibm · websphere application server30 июл. 2026 г.
- CVE-2024-209830Наблюдать
Download Manager <= 3.2.89 - Improper Authorization via protectMediaLibrary
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %w3eden · download manager13 июн. 2024 г.
- CVE-2025-4124830Наблюдать
CVE-2025-41248: Spring Security authorization bypass for method security annotations on parameterized types
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %vmware · spring security16 сент. 2025 г.