VulnSea

CWE-288

CVEs classified under CWE-288, newest first.

73 CVEsRSS

CVE-2026-20079Critical· 10.0CISA KEVPoC
6mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

▾ Hadalcisco · secure_firewall_management_centerEPSS 88%via NVD
CVE-2026-23760Critical· 9.8CISA KEVPoC
8mo ago

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a r…

▾ Hadalsmartertools · smartermailEPSS 97%via NVD
CVE-2025-3652Medium· 5.3
8mo ago

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints

Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows unauthorized access to private audio recordings by exploiting sequential audio IDs and insecure assignment endpoints. A…

▾ Sunlitpetlibro · petlibroEPSS 0.23%via NVD
CVE-2025-9967Critical· 9.8PoC
11mo ago

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7

The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.7. This is due to the plugin not properly validating a user's identity prior to upda…

▾ AbyssalEPSS 0.43%via NVD
CVE-2025-57819Critical· 9.8CISA KEV0dayPoC
1y ago

FreePBX is an open-source web-based graphical user interface

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrar…

▾ Hadalsangoma · freepbxEPSS 85%via NVD
CVE-2025-54738Critical· 9.8
1y ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Authentication Abuse.This issue affects Jobmonster: from n/a through <= 4.7.9.

Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster noo-jobmonster allows Authentication Abuse.This issue affects Jobmonster: from n/a through <= 4.7.9.

▾ MidnightEPSS 0.42%via NVD
CVE-2025-54725Critical· 9.8
1y ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.This issue affects Golo: from n/a through <= 1.7.0.

Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.This issue affects Golo: from n/a through <= 1.7.0.

▾ MidnightEPSS 0.42%via NVD
CVE-2025-34520Critical· 9.8
1y ago

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts

An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exp…

▾ Midnightarcserve · udpEPSS 0.37%via NVD
CVE-2025-40581High· 7.1
1y ago

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed)

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass. This could allow a non…

▾ Twilightsiemens · scalance_lpe9403_firmwareEPSS 0.15%via NVD
CVE-2025-24472High· 8.1CISA KEVPoC
1y ago

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…

▾ Abyssalfortinet · fortiproxyEPSS 7.2%via NVD
CVE-2024-55591Critical· 9.8CISA KEV0dayPoC
1y ago

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain supe…

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain supe…

▾ Hadalfortinet · fortiproxyEPSS 94%via NVD
CVE-2024-49604Critical· 9.8
1y ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.

▾ Midnightnajeebmedia · memberheroEPSS 0.53%via NVD
CVE-2023-20269Medium· 5.0CISA KEV
3y ago

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

▾ Midnightcisco · adaptive_security_appliance_softwareEPSS 25%via NVD
CWE-288 vulnerabilities (CVEs) — page 3 · VulnSea