CWE-294 · 269 записей
Authentication Bypass by Capture-replay
CVE этого класса
269 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2017-3191Эксплойта нет | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.d-link · dir-130 firmware · CWE-294 | Критическая9,8 | — | 62,5 % | 15 дек. 2017 г. |
52В плане | CVE-2023-49231Эксплойта нет | An authentication bypass vulnerability was found in Stilog Visual Planning 8.CWE-294 | Критическая9,8 | — | 42,9 % | 29 мар. 2024 г. |
43В плане | CVE-2022-22806Эксплойта нет | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malschneider-electric · smt series 1015 ups firmware · CWE-294 | Критическая9,8 | — | 12,5 % | 9 мар. 2022 г. |
41В плане | CVE-2017-6034Эксплойта нет | Schneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replayschneider-electric · modbus firmware · CWE-294 | Критическая9,8 | — | 5,2 % | 29 июн. 2017 г. |
40В плане | CVE-2018-7790Эксплойта нет | An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firschneider-electric · modicon m221 firmware · CWE-294 | Критическая9,8 | — | 2,5 % | 29 авг. 2018 г. |
40В плане | CVE-2025-49752Эксплойта нет | Azure Bastion Elevation of Privilege Vulnerabilitymicrosoft · azure bastion developer · CWE-294 | Критическая10,0 | — | 0,9 % | 20 нояб. 2025 г. |
39Наблюдать | CVE-2023-30909Эксплойта нет | A remote authentication bypass issue exists in some OneView APIs.hp · oneview · CWE-294 | Критическая9,8 | — | 1,5 % | 14 сент. 2023 г. |
39Наблюдать | CVE-2018-17932Эксплойта нет | JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, whicjuuko · k-800 firmware · CWE-294 | Критическая9,8 | — | 1,5 % | 2 нояб. 2020 г. |
39Наблюдать | CVE-2018-19025Эксплойта нет | In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmwarejuuko · k-808 firmware · CWE-294 | Критическая9,8 | — | 1,5 % | 2 нояб. 2020 г. |
39Наблюдать | CVE-2022-45789Эксплойта нет | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the cschneider-electric · ecostruxure control expert · CWE-294 | Критическая9,8 | — | 1,5 % | 31 янв. 2023 г. |
39Наблюдать | CVE-2019-18226Эксплойта нет | Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras andhoneywell · h2w2pc1m firmware · CWE-294 | Критическая9,8 | — | 1,4 % | 31 окт. 2019 г. |
39Наблюдать | CVE-2022-37011Эксплойта нет | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All vemendix · saml · CWE-294 | Критическая9,8 | — | 1,2 % | 13 сент. 2022 г. |
39Наблюдать | CVE-2022-29334Эксплойта нет | An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.h project · h · CWE-294 | Критическая9,8 | — | 1,2 % | 24 мая 2022 г. |
39Наблюдать | CVE-2021-38459Эксплойта нет | The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level.auvesy · versiondog · CWE-294 | Критическая9,8 | — | 1,0 % | 22 окт. 2021 г. |
39Наблюдать | CVE-2023-1886Эксплойта нет | Authentication Bypass by Capture-replay in thorsten/phpmyfaqphpmyfaq · phpmyfaq · CWE-294 | Критическая9,8 | — | 0,9 % | 5 апр. 2023 г. |
39Наблюдать | CVE-2022-36089Эксплойта нет | VelaUX APIServer vulnerable to Authentication Bypass by Capture-replaykubevela · kubevela · CWE-294 | Критическая9,8 | — | 0,9 % | 7 сент. 2022 г. |
39Наблюдать | CVE-2023-1537Эксплойта нет | Authentication Bypass by Capture-replay in answerdev/answeranswer · answer · CWE-294 | Критическая9,8 | — | 0,8 % | 21 мар. 2023 г. |
39Наблюдать | CVE-2021-22640Эксплойта нет | Ovarro TBox Insufficiently Protected Credentialsovarro · twinsoft · CWE-294 | Критическая9,8 | — | 0,8 % | 28 июл. 2022 г. |
39Наблюдать | CVE-2026-65905Эксплойта нет | Apache Tomcat: Limited replay attack possible with DIGEST authenticationapache · tomcat · CWE-294 | Критическая9,8 | — | 0,8 % | 25 авг. 2026 г. |
39Наблюдать | CVE-2022-44457Эксплойта нет | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All vemendix · saml · CWE-294 | Критическая9,8 | — | 0,7 % | 8 нояб. 2022 г. |
39Наблюдать | CVE-2023-0014Эксплойта нет | Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platformsap · netweaver application server abap · CWE-294 | Критическая9,8 | — | 0,7 % | 10 янв. 2023 г. |
39Наблюдать | CVE-2026-11856Эксплойта нет | cross-origin Digest auth state leakhaxx · curl · CWE-294 | Критическая9,8 | — | 0,7 % | 3 июл. 2026 г. |
39Наблюдать | CVE-2026-68079Эксплойта нет | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replayapache · cxf · CWE-294 | Критическая9,8 | — | 0,7 % | 6 авг. 2026 г. |
39Наблюдать | CVE-2026-28564Эксплойта нет | Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentialsapache software foundation · apache iotdb · CWE-294 | Критическая9,8 | — | 0,7 % | 10 июл. 2026 г. |
39Наблюдать | CVE-2024-38438Эксплойта нет | D-Link - CWE-294: Authentication Bypass by Capture-replaydlink · dsl-225 firmware · CWE-294 | Критическая9,8 | — | 0,7 % | 21 июл. 2024 г. |
- CVE-2017-319158В плане
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.
КритическаяCVSS 9,8Эксплойта нетEPSS 63 %d-link · dir-130 firmware15 дек. 2017 г.
- CVE-2023-4923152В плане
An authentication bypass vulnerability was found in Stilog Visual Planning 8.
КритическаяCVSS 9,8Эксплойта нетEPSS 43 %29 мар. 2024 г.
- CVE-2022-2280643В плане
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a mal
КритическаяCVSS 9,8Эксплойта нетEPSS 12 %schneider-electric · smt series 1015 ups firmware9 мар. 2022 г.
- CVE-2017-603441В плане
Schneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replay
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %schneider-electric · modbus firmware29 июн. 2017 г.
- CVE-2018-779040В плане
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to fir
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %schneider-electric · modicon m221 firmware29 авг. 2018 г.
- CVE-2025-4975240В плане
Azure Bastion Elevation of Privilege Vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %microsoft · azure bastion developer20 нояб. 2025 г.
- CVE-2023-3090939Наблюдать
A remote authentication bypass issue exists in some OneView APIs.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hp · oneview14 сент. 2023 г.
- CVE-2018-1793239Наблюдать
JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, whic
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %juuko · k-800 firmware2 нояб. 2020 г.
- CVE-2018-1902539Наблюдать
In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmware
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %juuko · k-808 firmware2 нояб. 2020 г.
- CVE-2022-4578939Наблюдать
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the c
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %schneider-electric · ecostruxure control expert31 янв. 2023 г.
- CVE-2019-1822639Наблюдать
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %honeywell · h2w2pc1m firmware31 окт. 2019 г.
- CVE-2022-3701139Наблюдать
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All ve
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mendix · saml13 сент. 2022 г.
- CVE-2022-2933439Наблюдать
An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %h project · h24 мая 2022 г.
- CVE-2021-3845939Наблюдать
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %auvesy · versiondog22 окт. 2021 г.
- CVE-2023-188639Наблюдать
Authentication Bypass by Capture-replay in thorsten/phpmyfaq
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpmyfaq · phpmyfaq5 апр. 2023 г.
- CVE-2022-3608939Наблюдать
VelaUX APIServer vulnerable to Authentication Bypass by Capture-replay
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %kubevela · kubevela7 сент. 2022 г.
- CVE-2023-153739Наблюдать
Authentication Bypass by Capture-replay in answerdev/answer
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %answer · answer21 мар. 2023 г.
- CVE-2021-2264039Наблюдать
Ovarro TBox Insufficiently Protected Credentials
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ovarro · twinsoft28 июл. 2022 г.
- CVE-2026-6590539Наблюдать
Apache Tomcat: Limited replay attack possible with DIGEST authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · tomcat25 авг. 2026 г.
- CVE-2022-4445739Наблюдать
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All ve
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mendix · saml8 нояб. 2022 г.
- CVE-2023-001439Наблюдать
Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sap · netweaver application server abap10 янв. 2023 г.
- CVE-2026-1185639Наблюдать
cross-origin Digest auth state leak
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %haxx · curl3 июл. 2026 г.
- CVE-2026-6807939Наблюдать
Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · cxf6 авг. 2026 г.
- CVE-2026-2856439Наблюдать
Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache software foundation · apache iotdb10 июл. 2026 г.
- CVE-2024-3843839Наблюдать
D-Link - CWE-294: Authentication Bypass by Capture-replay
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dlink · dsl-225 firmware21 июл. 2024 г.