İçeriğe atla
Noroxi

CWE-592 · 21 kayıt

DEPRECATED: Authentication Bypass Issues

Bu sınıftaki CVE’ler

21 kayıt

  • CVE-2018-10933
    64Bu hafta

    A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4.

    KritikCVSS 9,1SilahlaştırılmışEPSS %92

    libssh · libssh17 Eki 2018

  • CVE-2018-14643
    41Planlayın

    An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.

    KritikCVSS 9,8İstismar yokEPSS %6

    theforeman · foreman21 Eyl 2018

  • CVE-2014-5432
    40Planlayın

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via

    KritikCVSS 9,8İstismar yokEPSS %3

    baxter · sigma spectrum infusion system firmware26 Mar 2019

  • CVE-2018-1085
    40Planlayın

    openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to

    KritikCVSS 9,8İstismar yokEPSS %2

    redhat · openshift container platform15 Haz 2018

  • CVE-2019-3899
    39İzleyin

    It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misus

    KritikCVSS 9,8İstismar yokEPSS %1

    redhat · openshift container platform22 Nis 2019

  • CVE-2026-43512
    39İzleyin

    Apache Tomcat: Digest authenticator will authenticate any unknown user

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    apache · tomcat12 May 2026

  • CVE-2017-2684
    37İzleyin

    Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access

    KritikCVSS 9,0İstismar yokEPSS %2

    siemens · simatic logon21 Şub 2017

  • CVE-2018-10847
    35İzleyin

    prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass.

    YüksekCVSS 8,8İstismar yokEPSS %2

    prosody · prosody30 Tem 2018

  • CVE-2019-14843
    35İzleyin

    A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester.

    YüksekCVSS 8,8İstismar yokEPSS %1

    redhat · single sign-on7 Oca 2020

  • CVE-2017-2650
    34İzleyin

    It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM comm

    YüksekCVSS 8,5İstismar yokEPSS %1

    jenkins · pipeline classpath step27 Tem 2018

  • CVE-2016-8371
    32İzleyin

    The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

    YüksekCVSS 7,3Kavram kanıtıEPSS %11

    phoenixcontact · ilc plcs firmware5 Nis 2018

  • CVE-2019-10201
    32İzleyin

    It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures.

    YüksekCVSS 8,1İstismar yokEPSS %1

    redhat · keycloak14 Ağu 2019

  • CVE-2012-4688
    30İzleyin

    I-GEN opLYNX Central Authentication Bypass

    YüksekCVSS 7,5İstismar yokEPSS %2

    i-gen · oplynx31 Ara 2012

  • CVE-2017-7537
    30İzleyin

    It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package befor

    YüksekCVSS 7,5İstismar yokEPSS %1

    redhat · enterprise linux desktop26 Tem 2018

  • CVE-2017-7536
    28İzleyin

    In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, whi

    YüksekCVSS 7,0İstismar yokEPSS %0

    redhat · hibernate validator10 Oca 2018

  • CVE-2023-30971
    27İzleyin

    Gaia unauthenticated endpoints

    OrtaCVSS 6,8İstismar yokEPSS %0

    palantir · com.palantir.acme.gaia:gaia19 Ara 2025

  • CVE-2019-10198
    26İzleyin

    An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7.

    OrtaCVSS 6,5İstismar yokEPSS %2

    theforeman · foreman-tasks31 Tem 2019

  • CVE-2017-12164
    25İzleyin

    A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin.

    OrtaCVSS 6,4İstismar yokEPSS %0

    gnome · gnome display manager26 Tem 2018

  • CVE-2024-42759
    25İzleyin

    An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.

    OrtaCVSS 6,3İstismar yokEPSS %0

    ellevo · ellevo9 Eyl 2024

  • CVE-2016-8616
    24İzleyin

    A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and pass

    OrtaCVSS 5,9İstismar yokEPSS %3

    haxx · curl1 Ağu 2018

  • CVE-2014-2367
    17İzleyin

    Advantech WebAccess Authentication Bypass Issues

    OrtaCVSS 4,3İstismar yokEPSS %2

    advantech · advantech webaccess19 Tem 2014

Tüm zafiyet sınıfları