CVE z tagiem auth-bypass — 200 wyników. ← Wszystkie tagi

CVE-2024-7593 🔴 Łataj teraz KEV

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

9.8 CVSS
94.4% EPSS
ivantiauth-bypass 2024-08-13
CVE-2013-0632 🔴 Łataj teraz KEV

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and…

9.8 CVSS
92.7% EPSS
CVE-2020-5849 🔴 Łataj teraz KEV

Unraid 6.8.0 allows authentication bypass.

7.5 CVSS
93.8% EPSS
CVE-2026-20182 🔴 Łataj teraz KEV
network

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new vulnerability in the c…

10.0 CVSS
77.9% EPSS
ciscoauth-bypass 2026-05-14
CVE-2013-0625 🔴 Łataj teraz KEV

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January…

9.8 CVSS
78.3% EPSS
adobeauth-bypass 2013-01-09
CVE-2023-27351 🔴 Łataj teraz KEV

This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists wi…

7.5 CVSS
86.1% EPSS
papercutauth-bypass 2023-04-20
CVE-2026-0257 🔴 Łataj teraz KEV
network

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Pano…

9.1 CVSS
58.8% EPSS
CVE-2026-24858 🔴 Łataj teraz KEV
network

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, Fort…

9.8 CVSS
55.1% EPSS
fortinetauth-bypass 2026-01-27
CVE-2026-20127 🔴 Łataj teraz KEV
network

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBon…

10.0 CVSS
48.2% EPSS
ciscoauth-bypass 2026-02-25
CVE-2025-32975 🔴 Łataj teraz KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypas…

10.0 CVSS
45.4% EPSS
questauth-bypass 2025-06-24
CVE-2017-6862 🔴 Łataj teraz KEV
network

NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the…

9.8 CVSS
43.1% EPSS
CVE-2026-41940 🔴 Łataj teraz KEV

cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

9.8 CVSS
26.6% EPSS
CVE-2015-1130 🔴 Łataj teraz KEV
os

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

7.8 CVSS
20.4% EPSS
CVE-2026-48558 🔴 Łataj teraz KEV

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during l…

10.0 CVSS
0.7% EPSS
auth-bypass 2026-06-12
CVE-2024-44000 🔴 Łataj teraz

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a through < 6.5.0.1.

9.8 CVSS
92.9% EPSS
CVE-2023-2986 🔴 Łataj teraz

The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the a…

9.8 CVSS
91.4% EPSS
CVE-2023-2732 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API requ…

9.8 CVSS
90.0% EPSS
CVE-2024-50477 🔴 Łataj teraz

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a thr…

9.8 CVSS
82.2% EPSS
CVE-2023-2437 🔴 Łataj teraz

The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plu…

9.8 CVSS
76.8% EPSS
CVE-2016-6603 🔴 Łataj teraz

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

9.8 CVSS
70.3% EPSS
CVE-2023-2982 🔴 Łataj teraz

The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on …

9.8 CVSS
70.1% EPSS
CVE-2023-2734 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile RES…

9.8 CVSS
60.3% EPSS
CVE-2026-10523 🔴 Łataj teraz

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full admi…

9.9 CVSS
47.2% EPSS
ivantiauth-bypass 2026-06-09
CVE-2024-49328 🔴 Łataj teraz

Authentication Bypass Using an Alternate Path or Channel vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through <= 1.0.0.

9.8 CVSS
41.6% EPSS
CVE-2024-50478 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness vulnerability in swoopbrandon 1-Click Login: Passwordless Authentication swoop-password-free-authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwor…

9.8 CVSS
28.6% EPSS
swoopnowauth-bypass 2024-10-28
CVE-2026-26190 🔴 Łataj teraz

Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus exposes TCP port 9091 by default, which enables authentication bypasses. The /expr debug endpoint uses a w…

9.8 CVSS
27.7% EPSS
CVE-2016-10140 🟡 Monitoruj

Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all director…

7.5 CVSS
34.2% EPSS
CVE-2024-50488 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3.

8.8 CVSS
26.5% EPSS
CVE-2017-3791 🟠 Łataj w tym tygodniu
network

A vulnerability in the web-based GUI of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication and execute actions with administrator privileges. The vulnerability is due to a processin…

10.0 CVSS
12.2% EPSS
ciscoauth-bypass 2017-02-01
CVE-2017-14728 🟠 Łataj w tym tygodniu

An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force administrators to swit…

9.8 CVSS
10.3% EPSS
orpakauth-bypass 2019-06-03
CVE-2022-0992 🔴 Łataj teraz

The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to log in as administrative users due to missing identity verification on initial 2FA set-up that allo…

9.8 CVSS
4.4% EPSS
CVE-2026-1709 🟠 Łataj w tym tygodniu
os

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated client…

9.4 CVSS
5.8% EPSS
redhatauth-bypass 2026-02-06
CVE-2026-2624 🟠 Łataj w tym tygodniu

Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass. This issue affects Antikor Next Generation Fir…

9.8 CVSS
3.3% EPSS
epatiauth-bypass 2026-02-25
CVE-2017-14851 🟠 Łataj w tym tygodniu

A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack a…

9.8 CVSS
3.1% EPSS
CVE-2026-10561 🟠 Łataj w tym tygodniu

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the h…

10.0 CVSS
0.5% EPSS
langflowauth-bypass 2026-06-22
CVE-2026-50242 🟠 Łataj w tym tygodniu

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

10.0 CVSS
0.4% EPSS
CVE-2026-10611 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authentica…

10.0 CVSS
0.4% EPSS
CVE-2025-4378 🟠 Łataj w tym tygodniu

Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-AOF Mobile Application allows Authentication Abuse, Authentication Bypass. This issue affects ATA-AO…

10.0 CVSS
0.2% EPSS
auth-bypass 2025-06-24
CVE-2026-48567 🟠 Łataj w tym tygodniu
appscloud

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

10.0 CVSS
0.1% EPSS
CVE-2026-39858 🔴 Łataj teraz

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authenticatio…

10.0 CVSS
0.1% EPSS
CVE-2025-4320 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Authentication Bypass, Password Recovery E…

10.0 CVSS
0.1% EPSS
auth-bypass 2026-01-23
CVE-2026-35051 🔴 Łataj teraz

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is …

10.0 CVSS
0.0% EPSS
CVE-2026-25938 🟠 Łataj w tym tygodniu

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on …

9.8 CVSS
1.0% EPSS
CVE-2020-36713 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it pos…

9.8 CVSS
0.9% EPSS
CVE-2023-49231 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.

9.8 CVSS
0.8% EPSS
auth-bypass 2024-03-29
CVE-2026-25893 🟠 Łataj w tym tygodniu

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to gain administrative access via the h…

9.8 CVSS
0.7% EPSS
CVE-2023-2499 🟠 Łataj w tym tygodniu

The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social logi…

9.8 CVSS
0.7% EPSS
CVE-2025-34186 🔴 Łataj teraz

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters…

9.8 CVSS
0.7% EPSS
CVE-2026-32985 🔴 Łataj teraz

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a cr…

9.8 CVSS
0.6% EPSS
CVE-2023-49232 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the password reset PINs of administrative users.

9.8 CVSS
0.6% EPSS
auth-bypass 2024-03-29
CVE-2021-27130 🔴 Łataj teraz

Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.

9.8 CVSS
0.5% EPSS
CVE-2026-22192 🟠 Łataj w tym tygodniu

Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attack…

9.9 CVSS
0.0% EPSS
gvectorsauth-bypass 2026-03-13
CVE-2026-2095 🟠 Łataj w tym tygodniu

Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the sys…

9.8 CVSS
0.5% EPSS
flowringauth-bypass 2026-02-10
CVE-2023-2834 🔴 Łataj teraz

The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through th…

9.8 CVSS
0.5% EPSS
CVE-2026-8175 🟠 Łataj w tym tygodniu

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflo…

9.8 CVSS
0.5% EPSS
CVE-2026-12417 🟠 Łataj w tym tygodniu

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_pa…

9.8 CVSS
0.4% EPSS
CVE-2024-2161 🟠 Łataj w tym tygodniu

Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .

9.8 CVSS
0.4% EPSS
auth-bypass 2024-03-21
CVE-2026-36829 🟠 Łataj w tym tygodniu

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based on a user-controlled …

9.8 CVSS
0.4% EPSS
CVE-2019-25763 🟠 Łataj w tym tygodniu

WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers ca…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-06-20
CVE-2023-1833 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.

9.8 CVSS
0.4% EPSS
redlineauth-bypass 2023-04-14
CVE-2023-1803 🟠 Łataj w tym tygodniu

Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.

9.8 CVSS
0.4% EPSS
redlineauth-bypass 2023-04-14
CVE-2026-56265 🟠 Łataj w tym tygodniu

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any …

9.8 CVSS
0.4% EPSS
kidocodeauth-bypass 2026-06-21
CVE-2023-2733 🟠 Łataj w tym tygodniu

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST AP…

9.8 CVSS
0.4% EPSS
CVE-2026-5229 🟠 Łataj w tym tygodniu

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to a…

9.8 CVSS
0.4% EPSS
auth-bypass 2026-05-15
CVE-2024-50489 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= 1.…

9.8 CVSS
0.3% EPSS
CVE-2023-2027 🟠 Łataj w tym tygodniu

The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook logi…

9.8 CVSS
0.3% EPSS
CVE-2026-42302 🟠 Łataj w tym tygodniu

FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). The startup script entrypoint…

9.8 CVSS
0.3% EPSS
auth-bypassrce 2026-05-08
CVE-2025-67114 🟠 Łataj w tym tygodniu

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/r…

9.8 CVSS
0.3% EPSS
auth-bypass 2026-03-19
CVE-2023-2704 🔴 Łataj teraz

The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through…

9.8 CVSS
0.3% EPSS
CVE-2018-16988 🟠 Łataj w tym tygodniu

An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in t…

9.8 CVSS
0.3% EPSS
buffaloauth-bypass 2019-05-02
CVE-2024-49247 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-registration allows Authentication Bypass.This issue affects BuddyPress Better Registration: from n/a …

9.8 CVSS
0.3% EPSS
auth-bypass 2024-10-16
CVE-2023-3162 🟠 Łataj w tym tygodniu

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a …

9.8 CVSS
0.3% EPSS
CVE-2026-10580 🟠 Łataj w tym tygodniu

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in …

9.8 CVSS
0.3% EPSS
auth-bypass 2026-06-05
CVE-2023-49340 🟠 Łataj w tym tygodniu

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management …

9.8 CVSS
0.3% EPSS
auth-bypass 2024-03-09
CVE-2024-43234 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authentication Bypass.This issue affects Woffice: from n/a through <= 5.4.14.

9.8 CVSS
0.3% EPSS
xtendifyauth-bypass 2024-12-16
CVE-2026-8181 🟠 Łataj w tym tygodniu

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value h…

9.8 CVSS
0.3% EPSS
CVE-2026-3655 🟠 Łataj w tym tygodniu

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJ…

9.8 CVSS
0.3% EPSS
auth-bypass 2026-05-29
CVE-2026-0545 🔴 Łataj teraz

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the rep…

9.8 CVSS
0.3% EPSS
CVE-2026-6886 🟠 Łataj w tym tygodniu

Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.

9.8 CVSS
0.3% EPSS
auth-bypass 2026-04-23
CVE-2026-8760 🟠 Łataj w tym tygodniu

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_l…

9.8 CVSS
0.3% EPSS
auth-bypass 2026-05-27
CVE-2026-20998 🟠 Łataj w tym tygodniu

Improper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.

9.8 CVSS
0.2% EPSS
samsungauth-bypass 2026-03-16
CVE-2026-36537 🟠 Łataj w tym tygodniu

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/co…

9.8 CVSS
0.2% EPSS
auth-bypass 2026-06-15
CVE-2026-4670 🟠 Łataj w tym tygodniu

Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024…

9.8 CVSS
0.2% EPSS
progressauth-bypass 2026-04-30
CVE-2026-9141 🟠 Łataj w tym tygodniu

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access internal application pages …

9.8 CVSS
0.2% EPSS
auth-bypass 2026-05-20
CVE-2025-41273 🟠 Łataj w tym tygodniu

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticat…

9.8 CVSS
0.2% EPSS
CVE-2024-49604 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7…

9.8 CVSS
0.2% EPSS
CVE-2026-3461 🟠 Łataj w tym tygodniu

The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.1.0. This is due to the `express_pay_product_page_pay_for_order()` function logging users …

9.8 CVSS
0.2% EPSS
auth-bypass 2026-04-15
CVE-2026-5722 🟠 Łataj w tym tygodniu

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verificat…

9.8 CVSS
0.2% EPSS
auth-bypass 2026-05-05
CVE-2024-50487 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authentication Bypass.This issue affects MaanStore API: from n/a through <= 1.0.1.

9.8 CVSS
0.2% EPSS
CVE-2026-6510 🟠 Łataj w tym tygodniu

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the …

9.8 CVSS
0.2% EPSS
CVE-2020-36724 🔴 Łataj teraz

The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passed to the hash_hmac() function and the use…

9.8 CVSS
0.2% EPSS
CVE-2023-3048 🔴 Łataj teraz

Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass.This issue affects Lockcell: before 15.

9.8 CVSS
0.2% EPSS
CVE-2026-29515 🟠 Łataj w tym tygodniu

MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and…

9.8 CVSS
0.2% EPSS
xiaomiauth-bypass 2026-03-11
CVE-2026-2991 🟠 Łataj w tym tygodniu

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not veri…

9.8 CVSS
0.2% EPSS
auth-bypass 2026-03-18
CVE-2023-3249 🟠 Łataj w tym tygodniu

The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_…

9.8 CVSS
0.2% EPSS
CVE-2026-44109 🟠 Łataj w tym tygodniu

OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and …

9.8 CVSS
0.2% EPSS
openclawauth-bypass 2026-05-06
CVE-2016-9366 🟠 Łataj w tym tygodniu

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series version…

9.8 CVSS
0.1% EPSS
moxaauth-bypass 2017-02-13
CVE-2026-43512 🟠 Łataj w tym tygodniu
apps

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9…

9.8 CVSS
0.1% EPSS
apacheauth-bypass 2026-05-12
CVE-2023-3050 🔴 Łataj teraz

Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass.This issue affects Lockcell: before 15.

9.8 CVSS
0.1% EPSS
CVE-2017-6034 🟠 Łataj w tym tygodniu

An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker…

9.8 CVSS
0.1% EPSS
CVE-2026-25555 🟠 Łataj w tym tygodniu

OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-06-08
CVE-2026-27842 🟠 Łataj w tym tygodniu

Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration.

9.8 CVSS
0.1% EPSS
auth-bypass 2026-03-11
CVE-2026-28514 🟠 Łataj w tym tygodniu

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.7, 7.11.4, 7.12.4, 7.13.3, and 8.0.0, a critical authentication bypass vulnerability exists in Rocke…

9.8 CVSS
0.1% EPSS
CVE-2024-50486 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through <= 1.0.5.

9.8 CVSS
0.1% EPSS
acnooauth-bypass 2024-10-28
CVE-2026-20997 🟠 Łataj w tym tygodniu

Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authentication.

9.8 CVSS
0.1% EPSS
samsungauth-bypass 2026-03-16
CVE-2026-30849 🟠 Łataj w tym tygodniu

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper…

9.8 CVSS
0.1% EPSS
mantisbtauth-bypass 2026-03-23
CVE-2026-24207 🟠 Łataj w tym tygodniu
os

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tamp…

9.8 CVSS
0.1% EPSS
linuxauth-bypassdos 2026-05-20
CVE-2025-54807 🟠 Łataj w tym tygodniu

The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system.

9.8 CVSS
0.1% EPSS
auth-bypass 2025-09-18
CVE-2025-1740 🟠 Łataj w tym tygodniu

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypass, Password Recovery Exploitation, Brute Force. This issue affects MyRezzta: from s2.03.01 before v…

9.8 CVSS
0.1% EPSS
auth-bypass 2025-09-03
CVE-2026-43575 🟠 Łataj w tym tygodniu

OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper ro…

9.8 CVSS
0.1% EPSS
openclawauth-bypass 2026-05-06
CVE-2026-10880 🟠 Łataj w tym tygodniu

OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to…

9.8 CVSS
0.1% EPSS
CVE-2026-30702 🟠 Łataj w tym tygodniu

The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web management interface. The login page does not properly enforce session validation, allowing attackers to …

9.8 CVSS
0.1% EPSS
auth-bypass 2026-03-18
CVE-2026-25035 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-03-25
CVE-2026-27049 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue affects Jobica Core: from n/a through <= 1.4.2.

9.8 CVSS
0.1% EPSS
auth-bypass 2026-03-25
CVE-2023-6153 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness vulnerability in TeoSOFT Software TeoBASE allows Authentication Bypass. This issue affects TeoBASE: through 20240327. NOTE: The vendor was contacted early about this disclosure …

9.8 CVSS
0.1% EPSS
auth-bypass 2024-03-27
CVE-2020-37228 🟠 Łataj w tym tygodniu

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA co…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-05-16
CVE-2023-4669 🟠 Łataj w tym tygodniu

Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 3001: before 3.2.20.0.

9.8 CVSS
0.1% EPSS
exagateauth-bypass 2023-09-14
CVE-2025-67446 🟠 Łataj w tym tygodniu

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-06-04
CVE-2024-1202 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affects Octopod: before v1.  NOTE: The vendor was contacted and it was learned that the product is not …

9.8 CVSS
0.1% EPSS
auth-bypass 2024-03-21
CVE-2026-40884 🔴 Łataj teraz

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' togeth…

9.8 CVSS
0.1% EPSS
CVE-2026-7567 🟠 Łataj w tym tygodniu

The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. This is due to improper input validation in the maybe_login_temporary_user() function, which fails to…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-05-01
CVE-2026-7458 🟠 Łataj w tym tygodniu

The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP cod…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-05-02
CVE-2023-4702 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digital Yepas: before 1.0.1.

9.8 CVSS
0.1% EPSS
yepasauth-bypass 2023-09-14
CVE-2025-8350 🟠 Łataj w tym tygodniu

Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affect…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-02-19
CVE-2026-6853 🟠 Łataj w tym tygodniu

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This issue affects Pause+ Mobile…

9.8 CVSS
0.1% EPSS
auth-bypass 2026-06-12
CVE-2026-36721 🟠 Łataj w tym tygodniu

A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.

9.8 CVSS
0.1% EPSS
auth-bypass 2026-06-09
CVE-2024-50503 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authentication Bypass.This issue affects User Toolkit: from n/a through <= 1.2.3.

9.8 CVSS
0.0% EPSS
auth-bypass 2024-10-30
CVE-2026-28252 🟠 Łataj w tym tygodniu

A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.

9.8 CVSS
0.0% EPSS
traneauth-bypass 2026-03-12
CVE-2026-20093 🟠 Łataj w tym tygodniu

A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as&nbsp;Admin. …

9.8 CVSS
0.0% EPSS
auth-bypass 2026-04-01
CVE-2017-20237 🟠 Łataj w tym tygodniu

Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in the master service that allows unauthenticated remote attackers to execute arbitrary commands with a…

9.8 CVSS
0.0% EPSS
auth-bypassrce 2026-04-03
CVE-2025-26966 🟠 Łataj w tym tygodniu

Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.5.

9.8 CVSS
0.0% EPSS
auth-bypass 2025-02-25
CVE-2023-3632 🟠 Łataj w tym tygodniu

Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App allows Authentication Abuse, Authentication Bypass. This issue affects Kunduz - Homework Helper App: …

9.8 CVSS
0.0% EPSS
kunduzauth-bypass 2023-08-09
CVE-2023-3000 🟠 Łataj w tym tygodniu

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technology ErMon allows Command Line Execution through SQL Injection, Authentication Bypass.This issue affect…

9.8 CVSS
0.0% EPSS
CVE-2024-0949 🟠 Łataj w tym tygodniu

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: befor…

9.8 CVSS
0.0% EPSS
auth-bypass 2024-06-27
CVE-2017-20234 🟠 Łataj w tym tygodniu

GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access by exploiting a hardcoded string in the authentication mechan…

9.8 CVSS
0.0% EPSS
auth-bypass 2026-04-03
CVE-2018-25236 🟠 Łataj w tym tygodniu

Hirschmann HiOS and HiSecOS products RSP, RSPE, RSPS, RSPL, MSP, EES, EESX, GRS, OS, RED, EAGLE contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers…

9.8 CVSS
0.0% EPSS
auth-bypass 2026-04-03
CVE-2023-46453 🟠 Łataj w tym tygodniu

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular expression. For example, thi…

9.8 CVSS
0.0% EPSS
auth-bypass 2026-05-08
CVE-2023-7103 🟠 Łataj w tym tygodniu

Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authentication Bypass. This issue affects UFace 5: through 12022024.

9.8 CVSS
0.0% EPSS
CVE-2023-4178 🟠 Łataj w tym tygodniu

Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1.

9.8 CVSS
0.0% EPSS
neutronauth-bypass 2023-09-05
CVE-2023-2713 🟠 Łataj w tym tygodniu

Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass.This issue affects Rental …

9.8 CVSS
0.0% EPSS
CVE-2023-2887 🟠 Łataj w tym tygodniu

Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

9.8 CVSS
0.0% EPSS
cbotauth-bypass 2023-05-25
CVE-2023-2958 🟠 Łataj w tym tygodniu

Authorization Bypass Through User-Controlled Key vulnerability in Origin Software ATS Pro allows Authentication Abuse, Authentication Bypass.This issue affects ATS Pro: before 20230714.

9.8 CVSS
0.0% EPSS
CVE-2024-14034 🟠 Łataj w tym tygodniu

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending spe…

9.8 CVSS
0.0% EPSS
auth-bypass 2026-04-02
CVE-2026-56782 🟠 Łataj w tym tygodniu

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which i…

9.8 CVSS
0.0% EPSS
auth-bypass 2026-06-29
CVE-2026-39962 🟠 Łataj w tym tygodniu

MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special elements in an LDAP query in ApacheAuthenticate.php allows LDAP injection via an unsanitized username v…

9.6 CVSS
0.3% EPSS
CVE-2024-23674 🟠 Łataj w tym tygodniu

The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify for access to governmen…

9.6 CVSS
0.1% EPSS
auth-bypass 2024-02-15
CVE-2026-56073 🟠 Łataj w tym tygodniu

Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification reques…

9.4 CVSS
0.2% EPSS
auth-bypass 2026-06-19
CVE-2026-42882 🟠 Łataj w tym tygodniu

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler…

9.4 CVSS
0.1% EPSS
CVE-2026-41448 🟠 Łataj w tym tygodniu

AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequence in the Admin-Token…

9.4 CVSS
0.1% EPSS
CVE-2026-25150 🟠 Łataj w tym tygodniu

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form fie…

9.3 CVSS
0.6% EPSS
CVE-2025-4383 🟠 Łataj w tym tygodniu

Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm. Tic. Ltd. Şti. Wi-Fi Cloud Hotspot allows Authentication Abuse, Authentication Bypass. This issue …

9.3 CVSS
0.3% EPSS
auth-bypass 2025-06-24
CVE-2023-2546 🟡 Monitoruj

The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. This is due to incorrect authentication checking in the 'wpus_allow_user_to_admin_bar_menu' function…

8.8 CVSS
2.4% EPSS
CVE-2026-48746 🟠 Łataj w tym tygodniu

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the Op…

9.1 CVSS
0.7% EPSS
vllmauth-bypass 2026-06-22
CVE-2026-55196 🟠 Łataj w tym tygodniu

Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is e…

9.1 CVSS
0.6% EPSS
auth-bypass 2026-06-17
CVE-2025-71327 🔴 Łataj teraz

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to re…

9.1 CVSS
0.5% EPSS
CVE-2026-25848 🟠 Łataj w tym tygodniu

In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible

9.1 CVSS
0.4% EPSS
CVE-2026-39999 🟠 Łataj w tym tygodniu
apps

Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 …

9.1 CVSS
0.4% EPSS
apacheauth-bypass 2026-06-19
CVE-2026-49952 🟠 Łataj w tym tygodniu

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exp…

9.1 CVSS
0.4% EPSS
auth-bypass 2026-06-15
CVE-2026-12628 🟠 Łataj w tym tygodniu

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in t…

9.1 CVSS
0.4% EPSS
ibmauth-bypass 2026-06-22
CVE-2026-48188 🟠 Łataj w tym tygodniu

An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthenticated SQL injection which can lead to an authentication bypass. This issue only affects the syste…

9.1 CVSS
0.3% EPSS
CVE-2026-40525 🔴 Łataj teraz

OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration value is unset or emp…

9.1 CVSS
0.3% EPSS
CVE-2026-49230 🟠 Łataj w tym tygodniu
apps

Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.  This issue affects Apache APISIX: from 3.8.0 throu…

9.1 CVSS
0.2% EPSS
apacheauth-bypass 2026-06-19
CVE-2021-22779 🟠 Łataj w tym tygodniu

Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Exper…

9.1 CVSS
0.2% EPSS
CVE-2026-33432 🔴 Łataj teraz

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly co…

9.1 CVSS
0.1% EPSS
CVE-2026-39339 🟠 Łataj w tym tygodniu

ChurchCRM is an open-source church management system. Prior to 7.1.0, a critical authentication bypass vulnerability in ChurchCRM's API middleware (ChurchCRM/Slim/Middleware/AuthMiddleware.php) allows unauthenticated at…

9.1 CVSS
0.1% EPSS
CVE-2026-34457 🟠 Łataj w tym tygodniu

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth…

9.1 CVSS
0.1% EPSS
auth-bypass 2026-04-14
CVE-2026-33843 🟠 Łataj w tym tygodniu
appscloud

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

9.1 CVSS
0.1% EPSS
CVE-2026-29000 🟠 Łataj w tym tygodniu

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs that allows remote attackers to forge authentication tokens. Attackers…

9.1 CVSS
0.1% EPSS
auth-bypass 2026-03-04
CVE-2026-7876 🟠 Łataj w tym tygodniu

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client may be able to take advantage of this vulnerability to access files in the server's local storage tha…

9.1 CVSS
0.1% EPSS
ibmauth-bypass 2026-05-27
CVE-2026-33409 🟠 Łataj w tym tygodniu

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as …

9.1 CVSS
0.0% EPSS
CVE-2026-44196 🟠 Łataj w tym tygodniu

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the …

9.1 CVSS
0.0% EPSS
auth-bypass 2026-05-12
CVE-2026-42889 🟠 Łataj w tym tygodniu

Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypass in the multi-document WebSocket endpoints. When authentication is configured, WebSocket connectio…

9.1 CVSS
0.0% EPSS
auth-bypass 2026-05-12
CVE-2026-36727 🟠 Łataj w tym tygodniu

An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.

9.1 CVSS
0.0% EPSS
auth-bypass 2026-06-09
CVE-2026-27478 🟠 Łataj w tym tygodniu

Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens)…

9.1 CVSS
0.0% EPSS
CVE-2017-20235 🟠 Łataj w tym tygodniu

ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in the web user interface that allows unauthenticated attackers to gain access to administrative functio…

9.1 CVSS
0.0% EPSS
CVE-2026-9051 🟠 Łataj w tym tygodniu

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or…

9.1 CVSS
0.0% EPSS
CVE-2026-30805 🟠 Łataj w tym tygodniu

Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800

9.1 CVSS
0.0% EPSS
articaauth-bypass 2026-05-12
CVE-2026-9090 🟠 Łataj w tym tygodniu

Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certifi…

9.1 CVSS
0.0% EPSS
auth-bypass 2026-05-28
CVE-2025-2311 🟠 Łataj w tym tygodniu

Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication Bypass, Interface Ma…

9.0 CVSS
0.0% EPSS
auth-bypass 2025-03-20
CVE-2026-7569 🟡 Monitoruj

Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User inte…

8.8 CVSS
0.7% EPSS
questauth-bypassxss 2026-06-25
CVE-2026-9780 🟡 Monitoruj

Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User inte…

8.8 CVSS
0.7% EPSS
questauth-bypassxss 2026-06-25
CVE-2023-1462 🟡 Monitoruj

Authorization Bypass Through User-Controlled Key vulnerability in Vadi Corporate Information Systems DigiKent allows Authentication Bypass, Authentication Abuse. This issue affects DigiKent: before 23.03.20.

8.8 CVSS
0.4% EPSS
vadiauth-bypass 2023-03-21
CVE-2026-49062 🟡 Monitoruj

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.

8.8 CVSS
0.3% EPSS
auth-bypass 2026-06-15
CVE-2024-7557 🟡 Monitoruj
os

A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models wit…

8.8 CVSS
0.3% EPSS
CVE-2022-34155 🟠 Łataj w tym tygodniu

Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.

8.8 CVSS
0.2% EPSS
CVE-2024-49675 🟡 Monitoruj

Authentication Bypass Using an Alternate Path or Channel vulnerability in Vitalii iBryl Switch User ibryl-switch-user allows Authentication Bypass.This issue affects iBryl Switch User: from n/a through <= 1.0.1.

8.8 CVSS
0.2% EPSS
CVE-2026-33289 🟡 Monitoruj

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an LDAP Injection vulnerability exists in the SuiteCRM authentication flow. Th…

8.8 CVSS
0.2% EPSS
suitecrmauth-bypass 2026-03-20
CVE-2026-5140 🟡 Monitoruj

Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Authentication Bypass. This issue affects Pardus Update: from 0.…

8.8 CVSS
0.1% EPSS
auth-bypass 2026-04-29
CVE-2026-33175 🟡 Monitoruj

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. Prior to version 17.4.0, an authentication bypass vulnerability in oauthenticator allows an attacker with an unv…

8.8 CVSS
0.1% EPSS
auth-bypass 2026-04-03
CVE-2025-67915 🟡 Monitoruj

Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: from n/a through <= 1.0.46.

8.8 CVSS
0.1% EPSS
auth-bypass 2026-01-08
CVE-2026-33622 🟠 Łataj w tym tygodniu

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary JavaScript execution through `POST /wait` and `POST /tabs/{id}/wait` when…

8.8 CVSS
0.1% EPSS
CVE-2026-34121 🟡 Monitoruj
network

An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent parsing and authorization logic in JSON requests during auth…

8.8 CVSS
0.1% EPSS
tp-linkauth-bypass 2026-04-02
CVE-2025-60041 🟡 Monitoruj

Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all allows Password Recovery Exploitation.This issue affects Emails Catch All: from n/a through <= 3.5.3…

8.8 CVSS
0.1% EPSS
auth-bypass 2025-10-22
CVE-2026-43569 🟡 Monitoruj

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can ex…

8.8 CVSS
0.1% EPSS
openclawauth-bypass 2026-05-05
CVE-2026-8621 🟡 Monitoruj

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject maliciou…

8.8 CVSS
0.1% EPSS
auth-bypass 2026-05-14
CVE-2026-24359 🟡 Monitoruj

Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4.

8.8 CVSS
0.1% EPSS
auth-bypass 2026-03-25
CVE-2023-4934 🟡 Monitoruj

Authorization Bypass Through User-Controlled Key vulnerability in Usta AYBS allows Authentication Abuse, Authentication Bypass. This issue affects AYBS: before 1.0.3.

8.8 CVSS
0.1% EPSS
ustaauth-bypass 2023-09-27
CVE-2026-5415 🟡 Monitoruj

The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is du…

8.8 CVSS
0.1% EPSS
auth-bypass 2026-06-05
CVE-2023-2065 🟡 Monitoruj

Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass.This issue affects Cargo Tracking System: before 3558f28 .

8.8 CVSS
0.1% EPSS
armoliauth-bypass 2023-05-24
CVE-2026-52754 🟡 Monitoruj

Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public c…

8.8 CVSS
0.1% EPSS
nsaauth-bypass 2026-06-10