CWE-304 · 35 kayıt
Missing Critical Step in Authentication
Bu sınıftaki CVE’ler
37 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-2302İstismar yok | LENZE: Missing password verification in authorisation procedurelenze · c520 firmware · CWE-304 | Kritik9,8 | — | %2,1 | 11 Tem 2022 |
40Planlayın | CVE-2024-2172İstismar yok | Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalationcyberlord92 · web application firewall – website security · CWE-304 | Kritik9,8 | — | %1,7 | 13 Mar 2024 |
39İzleyin | CVE-2011-3172İstismar yok | unix2_chkpwd do not check for a valid accountsuse · suse linux enterprise server · CWE-304 | Kritik9,8 | — | %1,0 | 8 Haz 2018 |
39İzleyin | CVE-2024-8954İstismar yok | Authentication Bypass in composiohq/composiocomposio · composio · CWE-304 | Kritik9,8 | — | %0,9 | 20 Mar 2025 |
39İzleyin | CVE-2025-24322İstismar yok | An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110.tenda · ac6 firmware · CWE-304 | Kritik9,8 | — | %0,6 | 20 Ağu 2025 |
39İzleyin | CVE-2024-45764İstismar yok | Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability.dell · enterprise sonic distribution · CWE-304 | Kritik9,8 | — | %0,5 | 8 Kas 2024 |
38İzleyin | CVE-2023-54391Kavram kanıtı | Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameterproxmox server solutions gmbh · proxmox virtual environment (ve) · CWE-304 | Kritik9,3 | — | %3,0 | 1 Eyl 2026 |
36İzleyin | CVE-2022-1065İstismar yok | Multi Factor Authentication Bypass in various versions of Abacus ERPabacus · abacus erp 2018 · CWE-304 | Yüksek8,8 | — | %2,9 | 19 Nis 2022 |
36İzleyin | CVE-2026-61466İstismar yok | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalationapache · cxf · CWE-304 | Kritik9,1 | — | %0,7 | 6 Ağu 2026 |
36İzleyin | CVE-2026-59564İstismar yok | Authentication bypass between ZCC and client connector portalzscaler · client connector · CWE-304 | Kritik9,1 | — | %0,5 | 24 Ağu 2026 |
36İzleyin | CVE-2026-94052İstismar yok | Apache MINA SSHD: LDAP password authentication ineffectiveapache software foundation · apache mina sshd · CWE-304 | Kritik9,1 | — | — | Bugün |
35İzleyin | CVE-2022-40622İstismar yok | WAVLINK Quantum D4G (WN531G3) Session Management by IP Addresswavlink · wn531g3 firmware · CWE-304 | Yüksek8,8 | — | %0,7 | 13 Eyl 2022 |
35İzleyin | CVE-2024-12048İstismar yok | IDOR Vulnerability in transformeroptimus/superagisuperagi · superagi · CWE-304 | Yüksek8,8 | — | %0,7 | 20 Mar 2025 |
34İzleyin | CVE-2026-67351İstismar yok | Serendipity < 2.6.1 Authentication Bypass via Username Collisions9y · serendipity · CWE-304 | Yüksek8,7 | — | %0,6 | 30 Tem 2026 |
34İzleyin | CVE-2026-76207İstismar yok | phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookiephpmyfaq · phpmyfaq · CWE-304 | Yüksek8,6 | — | %0,5 | 19 Ağu 2026 |
32İzleyin | CVE-2024-9216İstismar yok | Authentication Bypass in gaizhenbiao/ChuanhuChatGPTgaizhenbiao · chuanhuchatgpt · CWE-304 | Yüksek8,1 | — | %0,6 | 20 Mar 2025 |
32İzleyin | CVE-2026-42452İstismar yok | Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTPtermix-ssh · termix · CWE-304 | Yüksek8,1 | — | %0,4 | 8 May 2026 |
32İzleyin | CVE-2024-11302İstismar yok | Missing check_access in lollms_binding_infos in parisneo/lollmsparisneo · parisneo/lollms · CWE-304 | Yüksek8,0 | — | %0,2 | 20 Mar 2025 |
32İzleyin | CVE-2026-93994İstismar yok | Apache MINA SSHD: Repeated-publickey policy bypass on serverapache software foundation · apache mina sshd · CWE-304 | Yüksek8,1 | — | — | Bugün |
31İzleyin | CVE-2024-12136İstismar yok | Improper Access Control in Elfatek Elektronics' ANKA JPD-00028elfatek · anka jpd00028 firmware · CWE-304 | Yüksek7,8 | — | %0,2 | 19 Mar 2025 |
30İzleyin | CVE-2026-55957Kavram kanıtı | Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bindapache · tomcat · CWE-304 | Yüksek7,3 | — | %2,9 | 29 Haz 2026 |
30İzleyin | CVE-2022-2821İstismar yok | Missing Critical Step in Authentication in namelessmc/namelessnamelessmc · nameless · CWE-304 | Yüksek7,5 | — | %1,3 | 15 Ağu 2022 |
30İzleyin | CVE-2024-20153İstismar yok | In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID.linuxfoundation · yocto · CWE-304 | Yüksek7,5 | — | %0,3 | 6 Oca 2025 |
29İzleyin | CVE-2023-52424İstismar yok | The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WECWE-304 | Yüksek7,4 | — | %0,7 | 17 May 2024 |
29İzleyin | CVE-2026-40542İstismar yok | Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verificationapache · httpclient · CWE-304 | Yüksek7,3 | — | %0,7 | 22 Nis 2026 |
- CVE-2022-230240Planlayın
LENZE: Missing password verification in authorisation procedure
KritikCVSS 9,8İstismar yokEPSS %2lenze · c520 firmware11 Tem 2022
- CVE-2024-217240Planlayın
Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
KritikCVSS 9,8İstismar yokEPSS %2cyberlord92 · web application firewall – website security13 Mar 2024
- CVE-2011-317239İzleyin
unix2_chkpwd do not check for a valid account
KritikCVSS 9,8İstismar yokEPSS %1suse · suse linux enterprise server8 Haz 2018
- CVE-2024-895439İzleyin
Authentication Bypass in composiohq/composio
KritikCVSS 9,8İstismar yokEPSS %1composio · composio20 Mar 2025
- CVE-2025-2432239İzleyin
An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110.
KritikCVSS 9,8İstismar yokEPSS %1tenda · ac6 firmware20 Ağu 2025
- CVE-2024-4576439İzleyin
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1dell · enterprise sonic distribution8 Kas 2024
- CVE-2023-5439138İzleyin
Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
KritikCVSS 9,3Kavram kanıtıEPSS %3proxmox server solutions gmbh · proxmox virtual environment (ve)1 Eyl 2026
- CVE-2022-106536İzleyin
Multi Factor Authentication Bypass in various versions of Abacus ERP
YüksekCVSS 8,8İstismar yokEPSS %3abacus · abacus erp 201819 Nis 2022
- CVE-2026-6146636İzleyin
Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
KritikCVSS 9,1İstismar yokEPSS %1apache · cxf6 Ağu 2026
- CVE-2026-5956436İzleyin
Authentication bypass between ZCC and client connector portal
KritikCVSS 9,1İstismar yokEPSS %1zscaler · client connector24 Ağu 2026
- CVE-2026-9405236İzleyin
Apache MINA SSHD: LDAP password authentication ineffective
KritikCVSS 9,1İstismar yokapache software foundation · apache mina sshdBugün
- CVE-2022-4062235İzleyin
WAVLINK Quantum D4G (WN531G3) Session Management by IP Address
YüksekCVSS 8,8İstismar yokEPSS %1wavlink · wn531g3 firmware13 Eyl 2022
- CVE-2024-1204835İzleyin
IDOR Vulnerability in transformeroptimus/superagi
YüksekCVSS 8,8İstismar yokEPSS %1superagi · superagi20 Mar 2025
- CVE-2026-6735134İzleyin
Serendipity < 2.6.1 Authentication Bypass via Username Collision
YüksekCVSS 8,7İstismar yokEPSS %1s9y · serendipity30 Tem 2026
- CVE-2026-7620734İzleyin
phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie
YüksekCVSS 8,6İstismar yokEPSS %0phpmyfaq · phpmyfaq19 Ağu 2026
- CVE-2024-921632İzleyin
Authentication Bypass in gaizhenbiao/ChuanhuChatGPT
YüksekCVSS 8,1İstismar yokEPSS %1gaizhenbiao · chuanhuchatgpt20 Mar 2025
- CVE-2026-4245232İzleyin
Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTP
YüksekCVSS 8,1İstismar yokEPSS %0termix-ssh · termix8 May 2026
- CVE-2024-1130232İzleyin
Missing check_access in lollms_binding_infos in parisneo/lollms
YüksekCVSS 8,0İstismar yokEPSS %0parisneo · parisneo/lollms20 Mar 2025
- CVE-2026-9399432İzleyin
Apache MINA SSHD: Repeated-publickey policy bypass on server
YüksekCVSS 8,1İstismar yokapache software foundation · apache mina sshdBugün
- CVE-2024-1213631İzleyin
Improper Access Control in Elfatek Elektronics' ANKA JPD-00028
YüksekCVSS 7,8İstismar yokEPSS %0elfatek · anka jpd00028 firmware19 Mar 2025
- CVE-2026-5595730İzleyin
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
YüksekCVSS 7,3Kavram kanıtıEPSS %3apache · tomcat29 Haz 2026
- CVE-2022-282130İzleyin
Missing Critical Step in Authentication in namelessmc/nameless
YüksekCVSS 7,5İstismar yokEPSS %1namelessmc · nameless15 Ağu 2022
- CVE-2024-2015330İzleyin
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID.
YüksekCVSS 7,5İstismar yokEPSS %0linuxfoundation · yocto6 Oca 2025
- CVE-2023-5242429İzleyin
The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WE
YüksekCVSS 7,4İstismar yokEPSS %117 May 2024
- CVE-2026-4054229İzleyin
Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
YüksekCVSS 7,3İstismar yokEPSS %1apache · httpclient22 Nis 2026