CWE-294 · 269 records
Authentication Bypass by Capture-replay
CVEs in this class
269 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2017-3191No exploit | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.d-link · dir-130 firmware · CWE-294 | Critical9.8 | — | 62.5% | Dec 15, 2017 |
52Plan | CVE-2023-49231No exploit | An authentication bypass vulnerability was found in Stilog Visual Planning 8.CWE-294 | Critical9.8 | — | 42.9% | Mar 29, 2024 |
43Plan | CVE-2022-22806No exploit | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malschneider-electric · smt series 1015 ups firmware · CWE-294 | Critical9.8 | — | 12.5% | Mar 9, 2022 |
41Plan | CVE-2017-6034No exploit | Schneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replayschneider-electric · modbus firmware · CWE-294 | Critical9.8 | — | 5.2% | Jun 29, 2017 |
40Plan | CVE-2018-7790No exploit | An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firschneider-electric · modicon m221 firmware · CWE-294 | Critical9.8 | — | 2.5% | Aug 29, 2018 |
40Plan | CVE-2025-49752No exploit | Azure Bastion Elevation of Privilege Vulnerabilitymicrosoft · azure bastion developer · CWE-294 | Critical10.0 | — | 0.9% | Nov 20, 2025 |
39Monitor | CVE-2023-30909No exploit | A remote authentication bypass issue exists in some OneView APIs.hp · oneview · CWE-294 | Critical9.8 | — | 1.5% | Sep 14, 2023 |
39Monitor | CVE-2018-17932No exploit | JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, whicjuuko · k-800 firmware · CWE-294 | Critical9.8 | — | 1.5% | Nov 2, 2020 |
39Monitor | CVE-2018-19025No exploit | In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmwarejuuko · k-808 firmware · CWE-294 | Critical9.8 | — | 1.5% | Nov 2, 2020 |
39Monitor | CVE-2022-45789No exploit | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the cschneider-electric · ecostruxure control expert · CWE-294 | Critical9.8 | — | 1.5% | Jan 31, 2023 |
39Monitor | CVE-2019-18226No exploit | Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras andhoneywell · h2w2pc1m firmware · CWE-294 | Critical9.8 | — | 1.4% | Oct 31, 2019 |
39Monitor | CVE-2022-37011No exploit | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All vemendix · saml · CWE-294 | Critical9.8 | — | 1.2% | Sep 13, 2022 |
39Monitor | CVE-2022-29334No exploit | An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.h project · h · CWE-294 | Critical9.8 | — | 1.2% | May 24, 2022 |
39Monitor | CVE-2021-38459No exploit | The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level.auvesy · versiondog · CWE-294 | Critical9.8 | — | 1.0% | Oct 22, 2021 |
39Monitor | CVE-2023-1886No exploit | Authentication Bypass by Capture-replay in thorsten/phpmyfaqphpmyfaq · phpmyfaq · CWE-294 | Critical9.8 | — | 0.9% | Apr 5, 2023 |
39Monitor | CVE-2022-36089No exploit | VelaUX APIServer vulnerable to Authentication Bypass by Capture-replaykubevela · kubevela · CWE-294 | Critical9.8 | — | 0.9% | Sep 7, 2022 |
39Monitor | CVE-2023-1537No exploit | Authentication Bypass by Capture-replay in answerdev/answeranswer · answer · CWE-294 | Critical9.8 | — | 0.8% | Mar 21, 2023 |
39Monitor | CVE-2021-22640No exploit | Ovarro TBox Insufficiently Protected Credentialsovarro · twinsoft · CWE-294 | Critical9.8 | — | 0.8% | Jul 28, 2022 |
39Monitor | CVE-2026-65905No exploit | Apache Tomcat: Limited replay attack possible with DIGEST authenticationapache · tomcat · CWE-294 | Critical9.8 | — | 0.8% | Aug 25, 2026 |
39Monitor | CVE-2022-44457No exploit | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All vemendix · saml · CWE-294 | Critical9.8 | — | 0.7% | Nov 8, 2022 |
39Monitor | CVE-2023-0014No exploit | Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platformsap · netweaver application server abap · CWE-294 | Critical9.8 | — | 0.7% | Jan 10, 2023 |
39Monitor | CVE-2026-11856No exploit | cross-origin Digest auth state leakhaxx · curl · CWE-294 | Critical9.8 | — | 0.7% | Jul 3, 2026 |
39Monitor | CVE-2026-68079No exploit | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replayapache · cxf · CWE-294 | Critical9.8 | — | 0.7% | Aug 6, 2026 |
39Monitor | CVE-2026-28564No exploit | Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentialsapache software foundation · apache iotdb · CWE-294 | Critical9.8 | — | 0.7% | Jul 10, 2026 |
39Monitor | CVE-2024-38438No exploit | D-Link - CWE-294: Authentication Bypass by Capture-replaydlink · dsl-225 firmware · CWE-294 | Critical9.8 | — | 0.7% | Jul 21, 2024 |
- CVE-2017-319158Plan
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.
CriticalCVSS 9.8No exploitEPSS 63%d-link · dir-130 firmwareDec 15, 2017
- CVE-2023-4923152Plan
An authentication bypass vulnerability was found in Stilog Visual Planning 8.
CriticalCVSS 9.8No exploitEPSS 43%Mar 29, 2024
- CVE-2022-2280643Plan
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a mal
CriticalCVSS 9.8No exploitEPSS 12%schneider-electric · smt series 1015 ups firmwareMar 9, 2022
- CVE-2017-603441Plan
Schneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replay
CriticalCVSS 9.8No exploitEPSS 5%schneider-electric · modbus firmwareJun 29, 2017
- CVE-2018-779040Plan
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to fir
CriticalCVSS 9.8No exploitEPSS 2%schneider-electric · modicon m221 firmwareAug 29, 2018
- CVE-2025-4975240Plan
Azure Bastion Elevation of Privilege Vulnerability
CriticalCVSS 10.0No exploitEPSS 1%microsoft · azure bastion developerNov 20, 2025
- CVE-2023-3090939Monitor
A remote authentication bypass issue exists in some OneView APIs.
CriticalCVSS 9.8No exploitEPSS 2%hp · oneviewSep 14, 2023
- CVE-2018-1793239Monitor
JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, whic
CriticalCVSS 9.8No exploitEPSS 2%juuko · k-800 firmwareNov 2, 2020
- CVE-2018-1902539Monitor
In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmware
CriticalCVSS 9.8No exploitEPSS 2%juuko · k-808 firmwareNov 2, 2020
- CVE-2022-4578939Monitor
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the c
CriticalCVSS 9.8No exploitEPSS 1%schneider-electric · ecostruxure control expertJan 31, 2023
- CVE-2019-1822639Monitor
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and
CriticalCVSS 9.8No exploitEPSS 1%honeywell · h2w2pc1m firmwareOct 31, 2019
- CVE-2022-3701139Monitor
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All ve
CriticalCVSS 9.8No exploitEPSS 1%mendix · samlSep 13, 2022
- CVE-2022-2933439Monitor
An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.
CriticalCVSS 9.8No exploitEPSS 1%h project · hMay 24, 2022
- CVE-2021-3845939Monitor
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level.
CriticalCVSS 9.8No exploitEPSS 1%auvesy · versiondogOct 22, 2021
- CVE-2023-188639Monitor
Authentication Bypass by Capture-replay in thorsten/phpmyfaq
CriticalCVSS 9.8No exploitEPSS 1%phpmyfaq · phpmyfaqApr 5, 2023
- CVE-2022-3608939Monitor
VelaUX APIServer vulnerable to Authentication Bypass by Capture-replay
CriticalCVSS 9.8No exploitEPSS 1%kubevela · kubevelaSep 7, 2022
- CVE-2023-153739Monitor
Authentication Bypass by Capture-replay in answerdev/answer
CriticalCVSS 9.8No exploitEPSS 1%answer · answerMar 21, 2023
- CVE-2021-2264039Monitor
Ovarro TBox Insufficiently Protected Credentials
CriticalCVSS 9.8No exploitEPSS 1%ovarro · twinsoftJul 28, 2022
- CVE-2026-6590539Monitor
Apache Tomcat: Limited replay attack possible with DIGEST authentication
CriticalCVSS 9.8No exploitEPSS 1%apache · tomcatAug 25, 2026
- CVE-2022-4445739Monitor
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All ve
CriticalCVSS 9.8No exploitEPSS 1%mendix · samlNov 8, 2022
- CVE-2023-001439Monitor
Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
CriticalCVSS 9.8No exploitEPSS 1%sap · netweaver application server abapJan 10, 2023
- CVE-2026-1185639Monitor
cross-origin Digest auth state leak
CriticalCVSS 9.8No exploitEPSS 1%haxx · curlJul 3, 2026
- CVE-2026-6807939Monitor
Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
CriticalCVSS 9.8No exploitEPSS 1%apache · cxfAug 6, 2026
- CVE-2026-2856439Monitor
Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
CriticalCVSS 9.8No exploitEPSS 1%apache software foundation · apache iotdbJul 10, 2026
- CVE-2024-3843839Monitor
D-Link - CWE-294: Authentication Bypass by Capture-replay
CriticalCVSS 9.8No exploitEPSS 1%dlink · dsl-225 firmwareJul 21, 2024