CVE z tagiem auth-bypass — 200 wyników. ← Wszystkie tagi

CVE-2023-35078 🔴 Łataj teraz KEV

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

9.8 CVSS
100.0% EPSS
CVE-2022-40684 🔴 Łataj teraz KEV
network

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManag…

9.8 CVSS
100.0% EPSS
CVE-2024-0012 🔴 Łataj teraz KEV
network

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative act…

CVE-2024-55591 🔴 Łataj teraz KEV
network

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote atta…

9.8 CVSS
98.3% EPSS
fortinetauth-bypass 2025-01-14
CVE-2026-23760 🔴 Łataj teraz KEV

SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existin…

9.8 CVSS
96.3% EPSS
CVE-2024-51378 🔴 Łataj teraz KEV

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatu…

10.0 CVSS
94.7% EPSS
CVE-2024-53704 🔴 Łataj teraz KEV
network

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

9.8 CVSS
95.1% EPSS
CVE-2024-7593 🔴 Łataj teraz KEV

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

9.8 CVSS
94.4% EPSS
ivantiauth-bypass 2024-08-13
CVE-2013-0632 🔴 Łataj teraz KEV

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and…

9.8 CVSS
92.7% EPSS
CVE-2023-46805 🔴 Łataj teraz KEV

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

8.2 CVSS
100.0% EPSS
CVE-2024-51567 🔴 Łataj teraz KEV

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMi…

10.0 CVSS
86.7% EPSS
CVE-2021-30116 🔴 Łataj teraz KEV

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default U…

10.0 CVSS
85.7% EPSS
CVE-2020-5849 🔴 Łataj teraz KEV

Unraid 6.8.0 allows authentication bypass.

7.5 CVSS
93.8% EPSS
CVE-2026-20182 🔴 Łataj teraz KEV
network

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the c…

10.0 CVSS
77.9% EPSS
ciscoauth-bypass 2026-05-14
CVE-2013-0625 🔴 Łataj teraz KEV

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January…

9.8 CVSS
78.3% EPSS
adobeauth-bypass 2013-01-09
CVE-2023-27351 🔴 Łataj teraz KEV

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists wi…

7.5 CVSS
86.1% EPSS
papercutauth-bypass 2023-04-20
CVE-2026-16232 🔴 Łataj teraz KEV

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative priv…

9.8 CVSS
73.3% EPSS
CVE-2026-0257 🔴 Łataj teraz KEV
network

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Pano…

9.1 CVSS
58.8% EPSS
CVE-2026-24858 🔴 Łataj teraz KEV
network

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, Fort…

9.8 CVSS
55.1% EPSS
fortinetauth-bypass 2026-01-27
CVE-2026-20127 🔴 Łataj teraz KEV
network

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBon…

10.0 CVSS
48.2% EPSS
ciscoauth-bypass 2026-02-25
CVE-2021-22893 🔴 Łataj teraz KEV

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow…

10.0 CVSS
47.2% EPSS
CVE-2025-32975 🔴 Łataj teraz KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypas…

10.0 CVSS
45.4% EPSS
questauth-bypass 2025-06-24
CVE-2017-6862 🔴 Łataj teraz KEV
network

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the…

9.8 CVSS
43.1% EPSS
CVE-2026-41940 🔴 Łataj teraz KEV

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

9.8 CVSS
26.6% EPSS
CVE-2015-1130 🔴 Łataj teraz KEV
os

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

7.8 CVSS
20.4% EPSS
CVE-2026-48558 🔴 Łataj teraz KEV

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during l…

10.0 CVSS
1.2% EPSS
CVE-2023-20269 🔴 Łataj teraz KEV
network

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute fo…

5.0 CVSS
21.6% EPSS
ciscoauth-bypass 2023-09-06
CVE-2025-24472 🔴 Łataj teraz KEV
network

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated atta…

8.1 CVSS
3.3% EPSS
fortinetauth-bypass 2025-02-11
CVE-2026-18556 🔴 Łataj teraz KEV

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

7.4 CVSS
0.5% EPSS
n-ableauth-bypass 2026-08-01
CVE-2026-18577 🔴 Łataj teraz KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

0.0 CVSS
1.5% EPSS
auth-bypass 2026-08-02
CVE-2024-44000 🔴 Łataj teraz

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.

9.8 CVSS
92.9% EPSS
CVE-2023-2986 🔴 Łataj teraz

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the a…

9.8 CVSS
91.4% EPSS
CVE-2023-2732 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API requ…

9.8 CVSS
90.0% EPSS
CVE-2024-50477 🔴 Łataj teraz

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a thr…

9.8 CVSS
82.2% EPSS
CVE-2023-2437 🔴 Łataj teraz

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plu…

9.8 CVSS
76.8% EPSS
CVE-2016-6603 🔴 Łataj teraz

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

9.8 CVSS
70.3% EPSS
CVE-2023-2982 🔴 Łataj teraz

The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on …

9.8 CVSS
70.1% EPSS
CVE-2023-2734 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile RES…

9.8 CVSS
60.3% EPSS
CVE-2023-27823 🔴 Łataj teraz

An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.

9.8 CVSS
53.3% EPSS
optomaauth-bypass 2023-05-12
CVE-2026-10523 🔴 Łataj teraz

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full admi…

9.9 CVSS
47.2% EPSS
ivantiauth-bypass 2026-06-09
CVE-2024-49328 🔴 Łataj teraz

Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.

9.8 CVSS
41.6% EPSS
CVE-2025-34027 🔴 Łataj teraz

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint ca…

9.0 CVSS
45.2% EPSS
CVE-2026-20079 🔴 Łataj teraz

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to ob…

10.0 CVSS
35.9% EPSS
auth-bypass 2026-03-04
CVE-2024-50478 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness vulnerability in swoopbrandon 1-Click Login: Passwordless Authentication swoop-password-free-authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwor…

9.8 CVSS
28.6% EPSS
swoopnowauth-bypass 2024-10-28
CVE-2026-26190 🔴 Łataj teraz

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a w…

9.8 CVSS
27.7% EPSS
CVE-2023-36144 🟡 Monitoruj

An authentication bypass in Intelbras Switch SG 2404 MR in firmware 1.00.54 allows an unauthenticated attacker to download the backup file of the device, exposing critical information about the device configuration.

7.5 CVSS
36.5% EPSS
CVE-2016-10140 🟡 Monitoruj

Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all director…

7.5 CVSS
34.2% EPSS
CVE-2024-50488 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3.

8.8 CVSS
26.5% EPSS
CVE-2017-3791 🟠 Łataj w tym tygodniu
network

A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions with administrator privileges. The vulnerability is due to a processin…

10.0 CVSS
12.2% EPSS
ciscoauth-bypass 2017-02-01
CVE-2017-14728 🟠 Łataj w tym tygodniu

An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to swit…

9.8 CVSS
10.3% EPSS
orpakauth-bypass 2019-06-03
CVE-2026-59309 🟠 Łataj w tym tygodniu
cloud

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized acces…

9.8 CVSS
7.9% EPSS
vmwareauth-bypass 2026-07-30
CVE-2026-0545 🔴 Łataj teraz

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the rep…

9.8 CVSS
4.4% EPSS
CVE-2022-0992 🔴 Łataj teraz

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allo…

9.8 CVSS
4.4% EPSS
CVE-2022-47003 🟠 Łataj w tym tygodniu

A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.

9.8 CVSS
3.6% EPSS
CVE-2026-34415 🟠 Łataj w tym tygodniu

Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint that fails to block PHP-executable extensions .php4 due to an incorrect regex patter…

9.8 CVSS
3.6% EPSS
CVE-2026-1709 🟠 Łataj w tym tygodniu
os

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated client…

9.4 CVSS
5.4% EPSS
redhatauth-bypass 2026-02-06
CVE-2026-2624 🟠 Łataj w tym tygodniu

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass. This issue affects Antikor Next Generation Fir…

9.8 CVSS
3.3% EPSS
epatiauth-bypass 2026-02-25
CVE-2017-14851 🟠 Łataj w tym tygodniu

A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack a…

9.8 CVSS
3.1% EPSS
CVE-2021-44088 🔴 Łataj teraz

An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.

CVE-2020-24193 🔴 Łataj teraz

A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.

CVE-2026-24207 🟠 Łataj w tym tygodniu
os

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tamp…

9.8 CVSS
2.5% EPSS
linuxauth-bypassdos 2026-05-20
CVE-2026-15826 🟠 Łataj w tym tygodniu

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the ret…

9.8 CVSS
2.5% EPSS
auth-bypass 2026-08-15
CVE-2026-29000 🟠 Łataj w tym tygodniu

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers…

9.1 CVSS
5.9% EPSS
auth-bypass 2026-03-04
CVE-2021-44971 🟠 Łataj w tym tygodniu

Multiple Tenda devices are affected by authentication bypass, such as AC15V1.0 Firmware V15.03.05.20_multi?AC5V1.0 Firmware V15.03.06.48_multi and so on. an attacker can obtain sensitive information, and even combine it …

9.8 CVSS
2.1% EPSS
tendaauth-bypassrce 2022-01-28
CVE-2026-25555 🟠 Łataj w tym tygodniu

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header…

9.8 CVSS
1.5% EPSS
auth-bypass 2026-06-08
CVE-2026-10561 🟠 Łataj w tym tygodniu

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the h…

10.0 CVSS
0.5% EPSS
langflowauth-bypass 2026-06-22
CVE-2026-39858 🔴 Łataj teraz

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authenticatio…

10.0 CVSS
0.5% EPSS
CVE-2026-45336 🟠 Łataj w tym tygodniu

HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session cook…

10.0 CVSS
0.4% EPSS
auth-bypass 2026-07-16
CVE-2026-50242 🟠 Łataj w tym tygodniu

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

10.0 CVSS
0.4% EPSS
CVE-2026-56451 🟠 Łataj w tym tygodniu

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header. This could allow an unauthenticated re…

10.0 CVSS
0.4% EPSS
auth-bypass 2026-07-14
CVE-2026-10611 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authentica…

10.0 CVSS
0.4% EPSS
CVE-2026-62422 🟠 Łataj w tym tygodniu

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

10.0 CVSS
0.3% EPSS
CVE-2026-36829 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled …

9.8 CVSS
1.3% EPSS
CVE-2026-35051 🔴 Łataj teraz

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is …

10.0 CVSS
0.3% EPSS
CVE-2025-4378 🟠 Łataj w tym tygodniu

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AO…

10.0 CVSS
0.2% EPSS
auth-bypass 2025-06-24
CVE-2026-48567 🟠 Łataj w tym tygodniu
appscloud

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

10.0 CVSS
0.1% EPSS
CVE-2025-4320 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery E…

10.0 CVSS
0.1% EPSS
auth-bypass 2026-01-23
CVE-2026-25938 🟠 Łataj w tym tygodniu

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on …

9.8 CVSS
1.0% EPSS
CVE-2026-63722 🟠 Łataj w tym tygodniu

ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsani…

9.8 CVSS
1.0% EPSS
auth-bypassrce 2026-08-19
CVE-2017-20237 🟠 Łataj w tym tygodniu

Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with a…

9.8 CVSS
1.0% EPSS
auth-bypassrce 2026-04-03
CVE-2026-23600 🟠 Łataj w tym tygodniu

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

9.8 CVSS
1.0% EPSS
hpeauth-bypass 2026-03-02
CVE-2020-36713 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it pos…

9.8 CVSS
0.9% EPSS
CVE-2026-24270 🟠 Łataj w tym tygodniu

NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosur…

9.8 CVSS
0.8% EPSS
auth-bypassdos 2026-07-01
CVE-2023-49231 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.

9.8 CVSS
0.8% EPSS
auth-bypass 2024-03-29
CVE-2026-47865 🟠 Łataj w tym tygodniu
cloud

VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31…

9.8 CVSS
0.8% EPSS
broadcomauth-bypass 2026-07-18
CVE-2024-36265 🟠 Łataj w tym tygodniu
apps

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending speci…

9.8 CVSS
0.7% EPSS
apacheauth-bypass 2024-06-12
CVE-2026-17182 🟠 Łataj w tym tygodniu

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

9.8 CVSS
0.7% EPSS
ibmauth-bypass 2026-08-14
CVE-2026-25893 🟠 Łataj w tym tygodniu

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the h…

9.8 CVSS
0.7% EPSS
CVE-2025-65856 🔴 Łataj teraz

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video str…

9.8 CVSS
0.7% EPSS
CVE-2026-59243 🟠 Łataj w tym tygodniu
apps

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass auth…

9.8 CVSS
0.7% EPSS
apacheauth-bypass 2026-07-29
CVE-2023-2499 🟠 Łataj w tym tygodniu

The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social logi…

9.8 CVSS
0.7% EPSS
CVE-2025-34186 🔴 Łataj teraz

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters…

9.8 CVSS
0.7% EPSS
CVE-2026-28323 🟠 Łataj w tym tygodniu

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

9.8 CVSS
0.6% EPSS
CVE-2026-14245 🟠 Łataj w tym tygodniu

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due …

9.8 CVSS
0.6% EPSS
auth-bypass 2026-07-09
CVE-2026-32985 🔴 Łataj teraz

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a cr…

9.8 CVSS
0.6% EPSS
CVE-2023-49232 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the password reset PINs of administrative users.

9.8 CVSS
0.6% EPSS
auth-bypass 2024-03-29
CVE-2024-49604 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7…

9.8 CVSS
0.5% EPSS
CVE-2021-27130 🔴 Łataj teraz

Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.

9.8 CVSS
0.5% EPSS
CVE-2024-46442 🟠 Łataj w tym tygodniu

An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.

9.8 CVSS
0.5% EPSS
auth-bypass 2024-12-10
CVE-2026-14512 🟠 Łataj w tym tygodniu

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

9.8 CVSS
0.5% EPSS
CVE-2026-22192 🟠 Łataj w tym tygodniu

Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attack…

9.9 CVSS
0.0% EPSS
gvectorsauth-bypass 2026-03-13
CVE-2026-2095 🟠 Łataj w tym tygodniu

Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the sys…

9.8 CVSS
0.5% EPSS
flowringauth-bypass 2026-02-10
CVE-2018-25236 🟠 Łataj w tym tygodniu

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers…

9.8 CVSS
0.5% EPSS
auth-bypass 2026-04-03
CVE-2026-3655 🟠 Łataj w tym tygodniu

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJ…

9.8 CVSS
0.5% EPSS
auth-bypass 2026-05-29
CVE-2026-15964 🟠 Łataj w tym tygodniu

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — reg…

9.8 CVSS
0.5% EPSS
auth-bypass 2026-08-01
CVE-2026-29515 🟠 Łataj w tym tygodniu

MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and…

9.8 CVSS
0.5% EPSS
xiaomiauth-bypass 2026-03-11
CVE-2026-9141 🟠 Łataj w tym tygodniu

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access internal application pages …

9.8 CVSS
0.5% EPSS
auth-bypass 2026-05-20
CVE-2026-9192 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the p…

9.8 CVSS
0.5% EPSS
auth-bypass 2026-08-05
CVE-2024-14034 🟠 Łataj w tym tygodniu

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending spe…

9.8 CVSS
0.5% EPSS
auth-bypass 2026-04-02
CVE-2017-20234 🟠 Łataj w tym tygodniu

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechan…

9.8 CVSS
0.5% EPSS
auth-bypass 2026-04-03
CVE-2023-2834 🔴 Łataj teraz

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through th…

9.8 CVSS
0.5% EPSS
CVE-2026-8175 🟠 Łataj w tym tygodniu

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflo…

9.8 CVSS
0.5% EPSS
CVE-2026-12761 🟠 Łataj w tym tygodniu

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to …

9.8 CVSS
0.5% EPSS
auth-bypass 2026-07-10
CVE-2026-12417 🟠 Łataj w tym tygodniu

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_pa…

9.8 CVSS
0.4% EPSS
CVE-2026-5270 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP requ…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-07-14
CVE-2026-15013 🟠 Łataj w tym tygodniu

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAM…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-07-16
CVE-2025-63823 🟠 Łataj w tym tygodniu

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-08-05
CVE-2026-15303 🟠 Łataj w tym tygodniu

The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_s…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-08-15
CVE-2024-2161 🟠 Łataj w tym tygodniu

Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .

9.8 CVSS
0.4% EPSS
auth-bypass 2024-03-21
CVE-2019-25763 🟠 Łataj w tym tygodniu

WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers ca…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-06-20
CVE-2026-57807 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth S…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-07-10
CVE-2026-64827 🟠 Łataj w tym tygodniu

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function de…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-08-03
CVE-2023-1833 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.

9.8 CVSS
0.4% EPSS
redlineauth-bypass 2023-04-14
CVE-2023-1803 🟠 Łataj w tym tygodniu

Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.

9.8 CVSS
0.4% EPSS
redlineauth-bypass 2023-04-14
CVE-2026-71237 🟠 Łataj w tym tygodniu

Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query("select * from userlists where use…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-08-05
CVE-2025-41273 🟠 Łataj w tym tygodniu

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticat…

9.8 CVSS
0.4% EPSS
CVE-2026-56265 🟠 Łataj w tym tygodniu

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any …

9.8 CVSS
0.4% EPSS
kidocodeauth-bypass 2026-06-21
CVE-2026-56271 🟠 Łataj w tym tygodniu

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-07-12
CVE-2026-8457 🟠 Łataj w tym tygodniu

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decod…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-08-02
CVE-2026-71248 🟠 Łataj w tym tygodniu

Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or param…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-08-05
CVE-2025-56385 🟠 Łataj w tym tygodniu

A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before…

9.8 CVSS
0.4% EPSS
CVE-2026-37270 🟠 Łataj w tym tygodniu

Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.

9.8 CVSS
0.4% EPSS
auth-bypass 2026-07-07
CVE-2026-28564 🟠 Łataj w tym tygodniu

Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-07-10
CVE-2023-2733 🟠 Łataj w tym tygodniu

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST AP…

9.8 CVSS
0.4% EPSS
CVE-2026-5229 🟠 Łataj w tym tygodniu

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to a…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-05-15
CVE-2026-12692 🟠 Łataj w tym tygodniu

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

9.8 CVSS
0.4% EPSS
auth-bypass 2026-07-17
CVE-2024-50489 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= 1.…

9.8 CVSS
0.3% EPSS
CVE-2023-2027 🟠 Łataj w tym tygodniu

The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook logi…

9.8 CVSS
0.3% EPSS
CVE-2026-42302 🟠 Łataj w tym tygodniu

FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). The startup script entrypoint…

9.8 CVSS
0.3% EPSS
auth-bypassrce 2026-05-08
CVE-2026-15341 🟠 Łataj w tym tygodniu

The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` an…

9.8 CVSS
0.3% EPSS
auth-bypass 2026-08-15
CVE-2025-67114 🟠 Łataj w tym tygodniu

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/r…

9.8 CVSS
0.3% EPSS
auth-bypass 2026-03-19
CVE-2023-2704 🔴 Łataj teraz

The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through…

9.8 CVSS
0.3% EPSS
CVE-2018-16988 🟠 Łataj w tym tygodniu

An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in t…

9.8 CVSS
0.3% EPSS
buffaloauth-bypass 2019-05-02
CVE-2024-49247 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-registration allows Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a …

9.8 CVSS
0.3% EPSS
auth-bypass 2024-10-16
CVE-2023-3162 🟠 Łataj w tym tygodniu

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a …

9.8 CVSS
0.3% EPSS
CVE-2026-10580 🟠 Łataj w tym tygodniu

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in …

9.8 CVSS
0.3% EPSS
auth-bypass 2026-06-05
CVE-2025-56447 🟠 Łataj w tym tygodniu

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

9.8 CVSS
0.3% EPSS
auth-bypass 2025-10-22
CVE-2023-49340 🟠 Łataj w tym tygodniu

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management …

9.8 CVSS
0.3% EPSS
auth-bypass 2024-03-09
CVE-2024-43234 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authentication Bypass.This issue affects Woffice: from n/a through <= 5.4.14.

9.8 CVSS
0.3% EPSS
xtendifyauth-bypass 2024-12-16
CVE-2026-8181 🟠 Łataj w tym tygodniu

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value h…

9.8 CVSS
0.3% EPSS
CVE-2026-52134 🟠 Łataj w tym tygodniu

An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.

9.8 CVSS
0.3% EPSS
auth-bypass 2026-07-31
CVE-2026-6886 🟠 Łataj w tym tygodniu

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.

9.8 CVSS
0.3% EPSS
auth-bypass 2026-04-23
CVE-2026-8760 🟠 Łataj w tym tygodniu

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_l…

9.8 CVSS
0.3% EPSS
auth-bypass 2026-05-27
CVE-2026-20998 🟠 Łataj w tym tygodniu

Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.

9.8 CVSS
0.2% EPSS
samsungauth-bypass 2026-03-16
CVE-2026-36537 🟠 Łataj w tym tygodniu

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/co…

9.8 CVSS
0.2% EPSS
auth-bypass 2026-06-15
CVE-2026-4670 🟠 Łataj w tym tygodniu

Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024…

9.8 CVSS
0.2% EPSS
progressauth-bypass 2026-04-30
CVE-2026-18108 🟠 Łataj w tym tygodniu

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts t…

9.8 CVSS
0.2% EPSS
timleggeauth-bypass 2026-08-03
CVE-2026-3461 🟠 Łataj w tym tygodniu

The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to the `express_pay_product_page_pay_for_order()` function logging users …

9.8 CVSS
0.2% EPSS
auth-bypass 2026-04-15
CVE-2026-5722 🟠 Łataj w tym tygodniu

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verificat…

9.8 CVSS
0.2% EPSS
auth-bypass 2026-05-05
CVE-2024-50487 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= 1.0.1.

9.8 CVSS
0.2% EPSS
CVE-2026-6510 🟠 Łataj w tym tygodniu

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the …

9.8 CVSS
0.2% EPSS
CVE-2020-36724 🔴 Łataj teraz

The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passed to the hash_hmac() function and the use…

9.8 CVSS
0.2% EPSS
CVE-2023-3048 🔴 Łataj teraz

Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass.This issue affects Lockcell: before 15.

9.8 CVSS
0.2% EPSS
CVE-2026-2991 🟠 Łataj w tym tygodniu

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not veri…

9.8 CVSS
0.2% EPSS
auth-bypass 2026-03-18
CVE-2023-3249 🟠 Łataj w tym tygodniu

The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_…

9.8 CVSS
0.2% EPSS
CVE-2026-44109 🟠 Łataj w tym tygodniu

OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and …

9.8 CVSS
0.2% EPSS
openclawauth-bypass 2026-05-06
CVE-2016-9366 🟠 Łataj w tym tygodniu

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series version…

9.8 CVSS
0.1% EPSS
moxaauth-bypass 2017-02-13
CVE-2026-43512 🟠 Łataj w tym tygodniu
apps

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9…

9.8 CVSS
0.1% EPSS
apacheauth-bypass 2026-05-12
CVE-2023-3050 🔴 Łataj teraz

Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass.This issue affects Lockcell: before 15.

9.8 CVSS
0.1% EPSS
CVE-2017-6034 🟠 Łataj w tym tygodniu

An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker…

9.8 CVSS
0.1% EPSS
CVE-2026-27842 🟠 Łataj w tym tygodniu

Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration.

9.8 CVSS
0.1% EPSS
auth-bypass 2026-03-11
CVE-2026-28514 🟠 Łataj w tym tygodniu

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocke…

9.8 CVSS
0.1% EPSS
CVE-2024-50486 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through <= 1.0.5.

9.8 CVSS
0.1% EPSS
acnooauth-bypass 2024-10-28
CVE-2026-20997 🟠 Łataj w tym tygodniu

Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.

9.8 CVSS
0.1% EPSS
samsungauth-bypass 2026-03-16
CVE-2026-30849 🟠 Łataj w tym tygodniu

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper…

9.8 CVSS
0.1% EPSS
mantisbtauth-bypass 2026-03-23
CVE-2025-54807 🟠 Łataj w tym tygodniu

The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system.

9.8 CVSS
0.1% EPSS
auth-bypass 2025-09-18
CVE-2025-1740 🟠 Łataj w tym tygodniu

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypass, Password Recovery Exploitation, Brute Force. This issue affects MyRezzta: from s2.03.01 before v…

9.8 CVSS
0.1% EPSS
auth-bypass 2025-09-03
CVE-2026-43575 🟠 Łataj w tym tygodniu

OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper ro…

9.8 CVSS
0.1% EPSS
openclawauth-bypass 2026-05-06
CVE-2026-10880 🟠 Łataj w tym tygodniu

OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to…

9.8 CVSS
0.1% EPSS
CVE-2026-30702 🟠 Łataj w tym tygodniu

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to …

9.8 CVSS
0.1% EPSS
auth-bypass 2026-03-18
CVE-2026-25035 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-03-25
CVE-2026-27049 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue affects Jobica Core: from n/a through <= 1.4.2.

9.8 CVSS
0.1% EPSS
auth-bypass 2026-03-25
CVE-2023-6153 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness vulnerability in TeoSOFT Software TeoBASE allows Authentication Bypass. This issue affects TeoBASE: through 20240327. NOTE: The vendor was contacted early about this disclosure …

9.8 CVSS
0.1% EPSS
auth-bypass 2024-03-27
CVE-2020-37228 🟠 Łataj w tym tygodniu

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA co…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-05-16
CVE-2023-4669 🟠 Łataj w tym tygodniu

Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 3001: before 3.2.20.0.

9.8 CVSS
0.1% EPSS
exagateauth-bypass 2023-09-14
CVE-2025-67446 🟠 Łataj w tym tygodniu

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-06-04
CVE-2024-1202 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affects Octopod: before v1.  NOTE: The vendor was contacted and it was learned that the product is not …

9.8 CVSS
0.1% EPSS
auth-bypass 2024-03-21
CVE-2026-40884 🔴 Łataj teraz

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' togeth…

9.8 CVSS
0.1% EPSS
CVE-2026-7567 🟠 Łataj w tym tygodniu

The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-05-01
CVE-2026-7458 🟠 Łataj w tym tygodniu

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP cod…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-05-02
CVE-2023-4702 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digital Yepas: before 1.0.1.

9.8 CVSS
0.1% EPSS
yepasauth-bypass 2023-09-14
CVE-2025-8350 🟠 Łataj w tym tygodniu

Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affect…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-02-19
CVE-2026-6853 🟠 Łataj w tym tygodniu

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue affects Pause+ Mobile…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-06-12
CVE-2026-36721 🟠 Łataj w tym tygodniu

A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.

9.8 CVSS
0.1% EPSS
auth-bypass 2026-06-09
CVE-2024-50503 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authentication Bypass.This issue affects User Toolkit: from n/a through <= 1.2.3.

9.8 CVSS
0.0% EPSS
auth-bypass 2024-10-30
CVE-2026-28252 🟠 Łataj w tym tygodniu

A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.

9.8 CVSS
0.0% EPSS
traneauth-bypass 2026-03-12
CVE-2026-20093 🟠 Łataj w tym tygodniu

A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as&nbsp;Admin. …

9.8 CVSS
0.0% EPSS
auth-bypass 2026-04-01
CVE-2025-26966 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.5.

9.8 CVSS
0.0% EPSS
auth-bypass 2025-02-25
CVE-2023-3632 🟠 Łataj w tym tygodniu

Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App allows Authentication Abuse, Authentication Bypass. This issue affects Kunduz - Homework Helper App: …

9.8 CVSS
0.0% EPSS
kunduzauth-bypass 2023-08-09
CVE-2023-3000 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technology ErMon allows Command Line Execution through SQL Injection, Authentication Bypass.This issue affect…

9.8 CVSS
0.0% EPSS