The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
Volume of CVEs assigned to CWE-305 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
153 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-31161CRITICAL CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild i | Apr 3, 2025 | 9.8 | 98 | YES | YES |
CVE-2024-37085HIGH VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previ | Jun 25, 2024 | 7.2 | 78 | YES | NO |
CVE-2020-10923HIGH This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required t | Jul 28, 2020 | 8.8 | 77 | NO | YES |
CVE-2023-34124CRITICAL The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier vers | Jul 13, 2023 | 9.8 | 73 | NO | YES |
CVE-2023-28126MEDIUM An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the | May 9, 2023 | 5.9 | 56 | NO | NO |
CVE-2026-25555CRITICAL OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin acces | Jun 8, 2026 | 9.8 | 52 | NO | YES |
CVE-2023-0777CRITICAL Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4. | Feb 10, 2023 | 9.8 | 50 | NO | YES |
CVE-2022-2651CRITICAL Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. | Aug 4, 2022 | 9.8 | 48 | NO | YES |
CVE-2026-4670CRITICAL Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.
This issue affects MOVEit Automation: from 2025.0.0 be | Apr 30, 2026 | 9.8 | 47 | NO | NO |
CVE-2026-2652HIGH A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-n | May 15, 2026 | 8.6 | 45 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.