Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-305

Authentication Bypass by Primary Weakness

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

153
Assigned CVEs
144th
Commonality Rank
7.6
Avg CVSS
1.3%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-305 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 26, 2019
7 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

153 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-31161CRITICAL
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild i
Apr 3, 20259.898YESYES
CVE-2024-37085HIGH
VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previ
Jun 25, 20247.278YESNO
CVE-2020-10923HIGH
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required t
Jul 28, 20208.877NOYES
CVE-2023-34124CRITICAL
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier vers
Jul 13, 20239.873NOYES
CVE-2023-28126MEDIUM
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the
May 9, 20235.956NONO
CVE-2026-25555CRITICAL
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin acces
Jun 8, 20269.852NOYES
CVE-2023-0777CRITICAL
Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.
Feb 10, 20239.850NOYES
CVE-2022-2651CRITICAL
Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.
Aug 4, 20229.848NOYES
CVE-2026-4670CRITICAL
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 be
Apr 30, 20269.847NONO
CVE-2026-2652HIGH
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-n
May 15, 20268.645NOYES
View all 153 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
16%
19%
5.0-5.9
10%
16%
6.0-6.9
20%
26%
7.0-7.9
16%
11%
8.0-8.9
30%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
2 CVEs
1.3% of CVEs· 92nd percentile
Metasploit
2 CVEs
1.3% of CVEs· 90th percentile
Nuclei
6 CVEs
3.9% of CVEs· 94th percentile
ExploitDB
3 CVEs
2.0% of CVEs· 88th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products