Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authenticat
TYPO3 is an open source, PHP based web content management system. In versions on the 12.x branch prior to 12.4.31 LTS an
DCIM dcTrack allows an attacker to misuse certain remote access features. An authenticated user with access to the appli
An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vu
On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions with SINEMA Remote Connect Ed
Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after perfo
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior
On Elspec G5 devices through 1.2.2.19, a person with physical access to the device can reset the Admin password by inser
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 1
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attach
Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a u
Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install
An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the T
Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with
Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Fir
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass
Insufficient policy enforcement in Loader in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to bypass co
An issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbi
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.T
mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the R
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to a
Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-
An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows
Authentication bypass in some Zoom Rooms Clients before version 6.5.1 may allow an unauthenticated user to conduct a dis
Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android ver
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows
The issue was addressed by adding additional logic. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker with ph
Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerabi
In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to f
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses,
The credentials of the users stored in the system's local database can be used for the log in, making it possible for an
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthori
mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmw
This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanis
Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed
An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted req
In Teltonika Networks Remote Management System (RMS), it is possible to perform account pre-hijacking by misusing the in
An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login
An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to
Zed is a multiplayer code editor. Prior to version 0.197.3, in the Zed Agent Panel allowed for an AI agent to achieve Re
Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.
An authentication bypass vulnerability exists in LG Innotek camera models LND7210 and LNV7210R. The vulnerability allows
Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU
The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could al
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started