Skip to main content

CWE archive

CWE-288 CVEs

Programmatic archive

605 CVEs tagged with CWE-288252 Critical, 217 High, 124 Medium, 12 Low, 0 Unrated.

CVE-2026-27611

Published Feb 25, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can com…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-69985

Published Feb 24, 2026

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, w…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2026-2791

Published Feb 24, 2026

Mitigation bypass in the Networking: Cache component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-2784

Published Feb 24, 2026

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-2775

Published Feb 24, 2026

Mitigation bypass in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

CVSS 9.8 · Critical
evidence mentions
34
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-22341

Published Feb 20, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Case-Themes Booked booked allows Authentication Abuse.This issue affects Booked: from n/a through <= 3.0.…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-68895

Published Feb 20, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in ahachat AhaChat Messenger Marketing ahachat-messenger-marketing allows Password Recovery Exploitation.Thi…

CVSS 6.5 · Medium

CVE-2025-67998

Published Feb 20, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-el allows Authentication Abuse.This issue affects Miraculous…

CVSS 8.8 · High

CVE-2026-2540

Published Feb 15, 2026

The Micca KE700 system contains flawed resynchronization logic and is vulnerable to replay attacks. This attack requires sending two previously captured codes in a specific sequen…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-1618

Published Feb 13, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows Privilege Escalation. This issue affects FlexCity/Kiosk: f…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2020-37156

Published Feb 11, 2026

BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard without valid credentials. Attackers can exploit the vulnerab…

CVSS 6.9 · Medium

CVE-2026-1603

Published Feb 10, 2026

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

CVSS 8.6 · High
evidence mentions
9
Buzz score
68.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-2096

Published Feb 10, 2026

Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a spec…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-2095

Published Feb 10, 2026

Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-0948

Published Feb 4, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Privilege Escalation.This issue affects Microsoft Entra ID SSO…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13986

Published Jan 28, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass.This issue affects Disable Login Page: from 0.0.0 b…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13980

Published Jan 28, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CKEditor 5 Premium Features allows Functionality Bypass.This issue affects CKEditor 5 Premium Feat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21589

Published Jan 27, 2026

An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
21.9

CVE-2026-24858

Published Jan 27, 2026

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9,…

CVSS 9.8 · Critical
evidence mentions
18
Buzz score
74.4
KEV listed

CVE-2022-25369

Published Jan 23, 2026

An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if…

CVSS 9.8 · Critical

CVE-2025-69101

Published Jan 22, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Workreap Core workreap_core allows Authentication Abuse.This issue affects Workreap Core: from…

CVSS 9.8 · Critical

CVE-2026-23760

Published Jan 22, 2026

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous…

CVSS 9.3 · Critical
evidence mentions
16
Buzz score
73.3
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-22037

Published Jan 19, 2026

The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-10484

Published Jan 17, 2026

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.1. This is…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Showing 151-175 of 605 CVEsPage 7 of 25