NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read,
NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can re
WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassi
A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authe
A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out
PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the m
PingFederate using the PingOne MFA adapter allows a new MFA device to be paired without requiring second factor authenti
In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypa
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.2 could allow a remote user to perform unauthorized action
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPad
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Contr
A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulne
The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthenticated settings export in v
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower
A vulnerability in the remote access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firep
A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (A
An Authentication Bypass Using an Alternate Path or Channel vulnerability in the Schweitzer Engineering Laboratories Rea
A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.
Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional sof
All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the
After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to
An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) an
An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2)
SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ig
Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unau
Unauthorized access to Gateway user capabilities
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7000
A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and
This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also i
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the dis
A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading
An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used
A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensit
A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexe
PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions
An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locall
Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can g
PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite
Dell PowerStore versions 2.1.0.x contain an Authentication bypass vulnerability. A remote unauthenticated attacker could
Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated
Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without
When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Tim
Use of static encryption key material allows forging an authentication token to other users within a tenant organization
Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sa
A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4,
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started