Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

628 CVEs tagged with CWE-288262 Critical, 225 High, 129 Medium, 12 Low, 0 Unrated.

CVE-2023-39930

Published Oct 25, 2023

A first-factor authentication bypass vulnerability exists in the PingFederate with PingID Radius PCV when a MSCHAP authentication request is sent via a maliciously crafted RADIUS…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46319

Published Oct 23, 2023

WALLIX Bastion 9.x before 9.0.9 and 10.x before 10.0.5 allows unauthenticated access to sensitive information by bypassing access control on a network access administration web in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4957

Published Oct 11, 2023

A vulnerability of authentication bypass has been found on a Zebra Technologies ZTC ZT410-203dpi ZPL printer. This vulnerability allows an attacker that is in the same network as…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42793

Published Sep 19, 2023

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

CVSS 9.8 · Critical
evidence mentions
29
Buzz score
64.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2023-4702

Published Sep 14, 2023

Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digital Yepas: before 1.0.1.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-3162

Published Aug 31, 2023

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verifica…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2023-32002

Published Aug 21, 2023

The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users usi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-2834

Published Jun 30, 2023

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2023-30946

Published Jun 29, 2023

A security defect was identified in Foundry Issues. If a user was added to an issue on a resource that they did not have access to and consequently could not see, they could query…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-34335

Published Jun 12, 2023

AMI BMC contains a vulnerability in the IPMI handler, where an unauthenticated host is allowed to write to a host SPI flash, bypassing secure boot protections. An exploitation of…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2986

Published Jun 8, 2023

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryptio…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2021-4373

Published Jun 7, 2023

The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36724

Published Jun 7, 2023

The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36713

Published Jun 7, 2023

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'updat…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 501-525 of 628 CVEsPage 21 of 26