An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants ful
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited all
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or co
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the
Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy servi
The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5.
The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. Th
The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions u
The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including
Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often prov
The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and
An issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to execute arbitrary code via
The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypa
D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel
Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an
anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can app
The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable t
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ
The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,
An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting t
The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.
The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all version
The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. Thi
The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5
The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This
Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-re
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and incl
Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns al
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registrati
The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including
This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management
The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin
The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0.
The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. T
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to authentication bypass in all versi
Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allo
Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authe
Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-wo
The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is d
The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is d
Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authen
Frequently Asked Questions
What is CWE-288?
CWE-288 (CWE-288) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-288?
There are 652 CVE records associated with CWE-288 in our database. Of these, 255 are critical severity, 214 are high severity, and 133 are medium severity.
How can I protect against CWE-288 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-288 using AI-powered security agents.
Detect CWE-288 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-288 vulnerabilities across your infrastructure.
Get Started