Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-288 · Authentication bypassDefinition on MITRE ↗Clear

19 results

CVE-2026-18556
2026-08-04
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

CWE-288 · Authentication bypass
Refsuptime.n-able.comstatus.n-able.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-07
CVE-2026-18577
2026-08-03
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

CWE-288 · Authentication bypass
Refsdocumentation.n-able.comstatus.n-able.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-06
CVE-2026-1603
2026-03-09
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
Ivanti

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.

CWE-288 · Authentication bypass
Refshub.ivanti.comnvd.nist.gov
Federal remediation due 2026-03-23
CVE-2026-24858
2026-01-27
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

CWE-288 · Authentication bypass
RefsPlease adhere to Fortinet's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Fortinet products affected by this vulnerability. Apply any final mitigations provided by the vendor as soon as they become available. For more information please seefortinet.comnvd.nist.gov
Federal remediation due 2026-01-30
CVE-2026-23760
2026-01-26
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel VulnerabilityRansomware
SmarterTools

SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. This could allow an unauthenticated attacker to supply a target administrator username and a new password to reset the account, resulting in full administrative compromise of the SmarterMail instance.

CWE-288 · Authentication bypass
Refssmartertools.comnvd.nist.gov
Federal remediation due 2026-02-16
CVE-2025-34026
2026-01-22
Versa Concerto Improper Authentication Vulnerability
Versa

Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.

CWE-288 · Authentication bypass
Refssecurity-portal.versa-networks.comnvd.nist.gov
Federal remediation due 2026-02-12
CVE-2025-2747
2025-10-20
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
Kentico

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

CWE-288 · Authentication bypass
Refsdevnet.kentico.comnvd.nist.gov
Federal remediation due 2025-11-10
CVE-2025-2746
2025-10-20
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
Kentico

Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.

CWE-288 · Authentication bypass
Refsdevnet.kentico.comnvd.nist.gov
Federal remediation due 2025-11-10
CVE-2025-57819
2025-08-29
Sangoma FreePBX Authentication Bypass Vulnerability
Sangoma

Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.

CWE-89 · SQL injectionCWE-288 · Authentication bypass
Refsgithub.comnvd.nist.gov
Federal remediation due 2025-09-19
CVE-2025-4427
2025-05-19
Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
Ivanti

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

CWE-288 · Authentication bypass
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2025-06-09
CVE-2025-24472
2025-03-18
Fortinet FortiOS and FortiProxy Authentication Bypass VulnerabilityRansomware
Fortinet

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

CWE-288 · Authentication bypass
Refsfortiguard.fortinet.comnvd.nist.gov
Federal remediation due 2025-04-08
CVE-2024-55591
2025-01-14
Fortinet FortiOS and FortiProxy Authentication Bypass VulnerabilityRansomware
Fortinet

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

CWE-288 · Authentication bypass
Refsfortiguard.fortinet.comnvd.nist.gov
Federal remediation due 2025-01-21
CVE-2024-27198
2024-03-07
JetBrains TeamCity Authentication Bypass VulnerabilityRansomware
JetBrains

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

CWE-288 · Authentication bypass
Refsjetbrains.comblog.jetbrains.comnvd.nist.gov
Federal remediation due 2024-03-28
CVE-2024-1709
2024-02-22
ConnectWise ScreenConnect Authentication Bypass VulnerabilityRansomware
ConnectWise

ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.

CWE-288 · Authentication bypass
Refsconnectwise.comnvd.nist.gov
Federal remediation due 2024-02-29
CVE-2023-46747
2023-10-31
F5 BIG-IP Configuration Utility Authentication Bypass VulnerabilityRansomware
F5

F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.

CWE-288 · Authentication bypass
Refsmy.f5.comnvd.nist.gov
Federal remediation due 2023-11-21
CVE-2023-42793
2023-10-04
JetBrains TeamCity Authentication Bypass VulnerabilityRansomware
JetBrains

JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.

CWE-288 · Authentication bypass
Refsblog.jetbrains.comnvd.nist.gov
Federal remediation due 2023-10-25
CVE-2023-20269
2023-09-13
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access VulnerabilityRansomware
Cisco

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

CWE-288 · Authentication bypass
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2023-10-04
CVE-2022-40684
2022-10-11
Fortinet Multiple Products Authentication Bypass VulnerabilityRansomware
Fortinet

Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

CWE-288 · Authentication bypass
Refsfortiguard.comnvd.nist.gov
Federal remediation due 2022-11-01
CVE-2020-10148
2021-11-03
SolarWinds Orion Authentication Bypass Vulnerability
SolarWinds

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

CWE-288 · Authentication bypass
Refsnvd.nist.gov
Federal remediation due 2022-05-03