DVP-12SE11T - Password Protection Bypass
The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov
Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authenticat
Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce subacco
The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager password-po
Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent a
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.
Authentication Bypass Using an Alternate Path or Channel vulnerability in Convers Lab WP SmartPay smartpay allows Authen
The Nokri - Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in
Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authenti
The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a specially crafted HTTP header, an unaut
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all
An unauthenticated debug port may allow access to the device file system.
Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authent
Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP hea
A vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versio
The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification with
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.
The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. Th
The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is du
Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affe
The Orion Login with SMS plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includin
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.
The Bravis User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1.
The Service Finder SMS System plugin for WordPress is vulnerable to authentication bypass in all versions up to, and inc
Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the co
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunde
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 cont
VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious act
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, i
This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGE
Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co.,
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or Pos
Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a
An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.1
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Simple OAuth (OAuth2) & OpenID Connect
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS T
Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio
Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer,
An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started