Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authenticatio
An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that could allow authenticated
Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Cons
IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper a
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify functio
Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OA
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions start
The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' e
Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /a
Ironic-image is an OpenStack Ironic deployment packaged and configured by Metal3. When the reverse proxy mode is enabled
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentic
IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security all
IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially craft
Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Au
A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.
An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required
Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an
Izanami is a shared configuration service well-suited for micro-service architecture implementation. Attackers can bypas
The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin
The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5.
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This
The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This i
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, a
The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authe
The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in version
The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition fo
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to,
Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypa
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BI
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote att
The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up
The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is
An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted P
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3
The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2.
The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5
Authentication bypass vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and
A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unaut
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated
In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Setti
NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. Th
AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI fl
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started