CWE-302 · 39 kayıt
Authentication Bypass by Assumed-Immutable Data
Bu sınıftaki CVE’ler
39 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2024-43441Kavram kanıtı | Apache HugeGraph-Server: Fixed JWT Token(Secret)apache · hugegraph · CWE-302 | Kritik9,8 | — | %69,4 | 24 Ara 2024 |
40Planlayın | CVE-2016-9482İstismar yok | PHP FormMail Generator generates PHP code for standard web forms, and the code generated is vulnerable to authentication bypassjqueryform · php formmail generator · CWE-302 | Kritik9,8 | — | %4,5 | 13 Tem 2018 |
40Planlayın | CVE-2025-29813İstismar yok | Azure DevOps Elevation of Privilege Vulnerabilitymicrosoft · azure devops · CWE-302 | Kritik9,8 | — | %1,7 | 8 May 2025 |
39İzleyin | CVE-2024-4024İstismar yok | Authentication Bypass by Assumed-Immutable Data in GitLabgitlab · gitlab · CWE-302 | Yüksek8,8 | — | %14,9 | 25 Nis 2024 |
39İzleyin | CVE-2023-4669İstismar yok | Authentication Bypass in Exagate SYSGuard 3001exagate · sysguard 3001 firmware · CWE-302 | Kritik9,8 | — | %1,2 | 14 Eyl 2023 |
39İzleyin | CVE-2023-4612İstismar yok | MFA bypass in Apereo CASapereo · central authentication service · CWE-302 | Kritik9,8 | — | %0,9 | 9 Kas 2023 |
39İzleyin | CVE-2024-56404İstismar yok | In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation.oneidentity · identity manager · CWE-302 | Kritik9,9 | — | %0,7 | 24 Oca 2025 |
39İzleyin | CVE-2026-48781İstismar yok | Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgerygitroomhq · postiz-app · CWE-302 | Kritik9,9 | — | %0,3 | 17 Haz 2026 |
36İzleyin | CVE-2025-47158İstismar yok | Azure DevOps Server Elevation of Privilege Vulnerabilitymicrosoft · azure devops · CWE-302 | Kritik9,0 | — | %0,7 | 18 Tem 2025 |
36İzleyin | CVE-2026-39429İstismar yok | kcp's cache server is accessible without authentication or authorization checkskcp · kcp · CWE-302 | Kritik9,1 | — | %0,5 | 8 Nis 2026 |
35İzleyin | CVE-2024-49056İstismar yok | Airlift.microsoft.com Elevation of Privilege Vulnerabilitymicrosoft · airlift microsoft com · CWE-302 | Yüksek8,8 | — | %1,0 | 12 Kas 2024 |
35İzleyin | CVE-2022-22729İstismar yok | CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets.yokogawa · centum cs 3000 firmware · CWE-302 | Yüksek8,8 | — | %0,9 | 11 Mar 2022 |
35İzleyin | CVE-2024-12838İstismar yok | Changing Information Technology CGFIDO - Authentication Bypasschanging information technology · cgfido · CWE-302 | Yüksek8,8 | — | %0,7 | 30 Ara 2024 |
34İzleyin | CVE-2024-3741İstismar yok | Electrolink FM/DAB/TV Transmitter Authentication Bypass by Assumed-Immutable Dataelectrolink · compact dab transmitter · CWE-302 | Yüksek8,7 | — | %0,5 | 18 Nis 2024 |
34İzleyin | CVE-2024-47086İstismar yok | OTP Bypass Vulnerabilityapexsoftcell · ld geo · CWE-302 | Yüksek8,7 | — | %0,5 | 19 Eyl 2024 |
34İzleyin | CVE-2024-22179İstismar yok | Electrolink FM/DAB/TV Transmitter Authentication Bypass by Assumed-Immutable Dataelectrolink · compact dab transmitter · CWE-302 | Yüksek8,7 | — | %0,4 | 18 Nis 2024 |
32İzleyin | CVE-2026-50528İstismar yok | .NET Security Feature Bypass Vulnerabilitymicrosoft · .net · CWE-302 | Yüksek8,2 | — | %0,6 | 14 Tem 2026 |
32İzleyin | CVE-2026-5423İstismar yok | Subscription Authentication Bypass via Unverified connectionParams.jwtneo4j · graphql · CWE-302 | Yüksek8,2 | — | %0,6 | 6 Ağu 2026 |
32İzleyin | CVE-2025-24876İstismar yok | Authentication bypass via authorization code injection in SAP Approutersap_se · sap approuter node.js package · CWE-302 | Yüksek8,1 | — | %0,5 | 10 Şub 2025 |
32İzleyin | CVE-2025-8855İstismar yok | 2FA Expiry Bypass in Optimus Software's Brokerage Automationoptimus software · brokerage automation · CWE-302 | Yüksek8,1 | — | %0,4 | 14 Kas 2025 |
32İzleyin | CVE-2026-13267İstismar yok | Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Accessibm · security verify access · CWE-302 | Yüksek8,1 | — | %0,4 | 12 Ağu 2026 |
30İzleyin | CVE-2020-15074İstismar yok | OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens openvpn · openvpn access server · CWE-302 | Yüksek7,5 | — | %1,0 | 14 Tem 2020 |
30İzleyin | CVE-2022-3875İstismar yok | Click Studios Passwordstate API authentication bypass by assumed-immutable dataclickstudios · passwordstate · CWE-302 | Yüksek7,5 | — | %1,0 | 19 Ara 2022 |
30İzleyin | CVE-2025-26522İstismar yok | Authentication Bypass Vulnerability in RupeeWeb trading platformrupeeseed technology ventures · rupeeweb · CWE-302 | Yüksek7,5 | — | %0,4 | 14 Şub 2025 |
29İzleyin | CVE-2024-45370İstismar yok | An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System 2.6.1.0.socomec · easy config system · CWE-302 | Yüksek7,3 | — | %0,2 | 1 Ara 2025 |
- CVE-2024-4344160Bu hafta
Apache HugeGraph-Server: Fixed JWT Token(Secret)
KritikCVSS 9,8Kavram kanıtıEPSS %69apache · hugegraph24 Ara 2024
- CVE-2016-948240Planlayın
PHP FormMail Generator generates PHP code for standard web forms, and the code generated is vulnerable to authentication bypass
KritikCVSS 9,8İstismar yokEPSS %4jqueryform · php formmail generator13 Tem 2018
- CVE-2025-2981340Planlayın
Azure DevOps Elevation of Privilege Vulnerability
KritikCVSS 9,8İstismar yokEPSS %2microsoft · azure devops8 May 2025
- CVE-2024-402439İzleyin
Authentication Bypass by Assumed-Immutable Data in GitLab
YüksekCVSS 8,8İstismar yokEPSS %15gitlab · gitlab25 Nis 2024
- CVE-2023-466939İzleyin
Authentication Bypass in Exagate SYSGuard 3001
KritikCVSS 9,8İstismar yokEPSS %1exagate · sysguard 3001 firmware14 Eyl 2023
- CVE-2023-461239İzleyin
MFA bypass in Apereo CAS
KritikCVSS 9,8İstismar yokEPSS %1apereo · central authentication service9 Kas 2023
- CVE-2024-5640439İzleyin
In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privilege escalation.
KritikCVSS 9,9İstismar yokEPSS %1oneidentity · identity manager24 Oca 2025
- CVE-2026-4878139İzleyin
Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
KritikCVSS 9,9İstismar yokEPSS %0gitroomhq · postiz-app17 Haz 2026
- CVE-2025-4715836İzleyin
Azure DevOps Server Elevation of Privilege Vulnerability
KritikCVSS 9,0İstismar yokEPSS %1microsoft · azure devops18 Tem 2025
- CVE-2026-3942936İzleyin
kcp's cache server is accessible without authentication or authorization checks
KritikCVSS 9,1İstismar yokEPSS %1kcp · kcp8 Nis 2026
- CVE-2024-4905635İzleyin
Airlift.microsoft.com Elevation of Privilege Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1microsoft · airlift microsoft com12 Kas 2024
- CVE-2022-2272935İzleyin
CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets.
YüksekCVSS 8,8İstismar yokEPSS %1yokogawa · centum cs 3000 firmware11 Mar 2022
- CVE-2024-1283835İzleyin
Changing Information Technology CGFIDO - Authentication Bypass
YüksekCVSS 8,8İstismar yokEPSS %1changing information technology · cgfido30 Ara 2024
- CVE-2024-374134İzleyin
Electrolink FM/DAB/TV Transmitter Authentication Bypass by Assumed-Immutable Data
YüksekCVSS 8,7İstismar yokEPSS %0electrolink · compact dab transmitter18 Nis 2024
- CVE-2024-4708634İzleyin
OTP Bypass Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0apexsoftcell · ld geo19 Eyl 2024
- CVE-2024-2217934İzleyin
Electrolink FM/DAB/TV Transmitter Authentication Bypass by Assumed-Immutable Data
YüksekCVSS 8,7İstismar yokEPSS %0electrolink · compact dab transmitter18 Nis 2024
- CVE-2026-5052832İzleyin
.NET Security Feature Bypass Vulnerability
YüksekCVSS 8,2İstismar yokEPSS %1microsoft · .net14 Tem 2026
- CVE-2026-542332İzleyin
Subscription Authentication Bypass via Unverified connectionParams.jwt
YüksekCVSS 8,2İstismar yokEPSS %1neo4j · graphql6 Ağu 2026
- CVE-2025-2487632İzleyin
Authentication bypass via authorization code injection in SAP Approuter
YüksekCVSS 8,1İstismar yokEPSS %0sap_se · sap approuter node.js package10 Şub 2025
- CVE-2025-885532İzleyin
2FA Expiry Bypass in Optimus Software's Brokerage Automation
YüksekCVSS 8,1İstismar yokEPSS %0optimus software · brokerage automation14 Kas 2025
- CVE-2026-1326732İzleyin
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
YüksekCVSS 8,1İstismar yokEPSS %0ibm · security verify access12 Ağu 2026
- CVE-2020-1507430İzleyin
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens
YüksekCVSS 7,5İstismar yokEPSS %1openvpn · openvpn access server14 Tem 2020
- CVE-2022-387530İzleyin
Click Studios Passwordstate API authentication bypass by assumed-immutable data
YüksekCVSS 7,5İstismar yokEPSS %1clickstudios · passwordstate19 Ara 2022
- CVE-2025-2652230İzleyin
Authentication Bypass Vulnerability in RupeeWeb trading platform
YüksekCVSS 7,5İstismar yokEPSS %0rupeeseed technology ventures · rupeeweb14 Şub 2025
- CVE-2024-4537029İzleyin
An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System 2.6.1.0.
YüksekCVSS 7,3İstismar yokEPSS %0socomec · easy config system1 Ara 2025