Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On all
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to byp
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two featur
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe
An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not requi
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clie
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products li
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download data
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass
Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authenticat
An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated ne
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows
Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-e
Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Add
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability.
Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentica
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service all
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Ex
Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnera
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account tak
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Aut
The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/expr
A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application
Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-ht
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-managem
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and in
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-gua
Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-member
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authent
goshs is a SimpleHTTPServer written in Go. From version 1.1.0 to before version 2.0.0-beta.2, when using the Share Token
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they w
Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applica
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 249 CVE records associated with CWE-288 in our database. Of these, 72 are critical severity, 85 are high severity, and 63 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started