Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

605 CVEs tagged with CWE-288252 Critical, 217 High, 124 Medium, 12 Low, 0 Unrated.

CVE-2022-36093

Published Sep 8, 2022

XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart template, user accounts can b…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34372

Published Sep 1, 2022

Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact wi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-2031

Published Aug 25, 2022

A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and set of keys, allowing them to decrypt each other's tickets…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35869

Published Jul 25, 2022

This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31022

Published Jun 1, 2022

Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitat…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26865

Published May 26, 2022

Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit th…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32958

Published May 23, 2022

Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows an attacker with local command line interface access to ga…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-1681

Published May 12, 2022

Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31559

Published May 6, 2022

A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23722

Published May 2, 2022

When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Time Password, PingID or SMS authentication, an existing user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0992

Published Apr 19, 2022

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity ver…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 526-550 of 605 CVEsPage 22 of 25