Skip to content
Noroxi

CWE-294 · 269 records

Authentication Bypass by Capture-replay

CVEs in this class

269 records

  • D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.

    CriticalCVSS 9.8No exploitEPSS 63%

    d-link · dir-130 firmwareDec 15, 2017

  • An authentication bypass vulnerability was found in Stilog Visual Planning 8.

    CriticalCVSS 9.8No exploitEPSS 43%

    Mar 29, 2024

  • A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a mal

    CriticalCVSS 9.8No exploitEPSS 12%

    schneider-electric · smt series 1015 ups firmwareMar 9, 2022

  • Schneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replay

    CriticalCVSS 9.8No exploitEPSS 5%

    schneider-electric · modbus firmwareJun 29, 2017

  • An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to fir

    CriticalCVSS 9.8No exploitEPSS 2%

    schneider-electric · modicon m221 firmwareAug 29, 2018

  • Azure Bastion Elevation of Privilege Vulnerability

    CriticalCVSS 10.0No exploitEPSS 1%

    microsoft · azure bastion developerNov 20, 2025

  • A remote authentication bypass issue exists in some OneView APIs.

    CriticalCVSS 9.8No exploitEPSS 2%

    hp · oneviewSep 14, 2023

  • JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, whic

    CriticalCVSS 9.8No exploitEPSS 2%

    juuko · k-800 firmwareNov 2, 2020

  • In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmware

    CriticalCVSS 9.8No exploitEPSS 2%

    juuko · k-808 firmwareNov 2, 2020

  • A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the c

    CriticalCVSS 9.8No exploitEPSS 1%

    schneider-electric · ecostruxure control expertJan 31, 2023

  • Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and

    CriticalCVSS 9.8No exploitEPSS 1%

    honeywell · h2w2pc1m firmwareOct 31, 2019

  • A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All ve

    CriticalCVSS 9.8No exploitEPSS 1%

    mendix · samlSep 13, 2022

  • An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.

    CriticalCVSS 9.8No exploitEPSS 1%

    h project · hMay 24, 2022

  • The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level.

    CriticalCVSS 9.8No exploitEPSS 1%

    auvesy · versiondogOct 22, 2021

  • CVE-2023-1886
    39Monitor

    Authentication Bypass by Capture-replay in thorsten/phpmyfaq

    CriticalCVSS 9.8No exploitEPSS 1%

    phpmyfaq · phpmyfaqApr 5, 2023

  • VelaUX APIServer vulnerable to Authentication Bypass by Capture-replay

    CriticalCVSS 9.8No exploitEPSS 1%

    kubevela · kubevelaSep 7, 2022

  • CVE-2023-1537
    39Monitor

    Authentication Bypass by Capture-replay in answerdev/answer

    CriticalCVSS 9.8No exploitEPSS 1%

    answer · answerMar 21, 2023

  • Ovarro TBox Insufficiently Protected Credentials

    CriticalCVSS 9.8No exploitEPSS 1%

    ovarro · twinsoftJul 28, 2022

  • Apache Tomcat: Limited replay attack possible with DIGEST authentication

    CriticalCVSS 9.8No exploitEPSS 1%

    apache · tomcatAug 25, 2026

  • A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All ve

    CriticalCVSS 9.8No exploitEPSS 1%

    mendix · samlNov 8, 2022

  • CVE-2023-0014
    39Monitor

    Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

    CriticalCVSS 9.8No exploitEPSS 1%

    sap · netweaver application server abapJan 10, 2023

  • cross-origin Digest auth state leak

    CriticalCVSS 9.8No exploitEPSS 1%

    haxx · curlJul 3, 2026

  • Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay

    CriticalCVSS 9.8No exploitEPSS 1%

    apache · cxfAug 6, 2026

  • Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials

    CriticalCVSS 9.8No exploitEPSS 1%

    apache software foundation · apache iotdbJul 10, 2026

  • D-Link - CWE-294: Authentication Bypass by Capture-replay

    CriticalCVSS 9.8No exploitEPSS 1%

    dlink · dsl-225 firmwareJul 21, 2024

All vulnerability classes