CWE-303 · 95 записей
Incorrect Implementation of Authentication Algorithm
CVE этого класса
95 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2023-29357Готовый эксплойт | Microsoft SharePoint Server Elevation of Privilege Vulnerabilitymicrosoft · sharepoint server · CWE-303 | Критическая9,8 | KEV | 100,0 % | 13 июн. 2023 г. |
58В плане | CVE-2020-8863Эксплойта нет | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-dlink · dir-878 firmware · CWE-303 | Высокая8,8 | — | 76,7 % | 23 мар. 2020 г. |
46В плане | CVE-2022-20695Эксплойта нет | Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerabilitycisco · wireless lan controller 8.10.151.0 · CWE-303 | Критическая10,0 | — | 19,8 % | 15 апр. 2022 г. |
41В плане | CVE-2024-4985Эксплойта нет | An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication github · enterprise server · CWE-303 | Критическая10,0 | — | 2,6 % | 20 мая 2024 г. |
40В плане | CVE-2018-4841Эксплойта нет | A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1).siemens · tim 1531 irc firmware · CWE-303 | Критическая9,8 | — | 4,7 % | 29 мар. 2018 г. |
40В плане | CVE-2025-13390Proof of concept | WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeoverwpdirectorykit · wp directory kit · CWE-303 | Критическая9,8 | — | 4,6 % | 3 дек. 2025 г. |
40В плане | CVE-2025-21311Эксплойта нет | Windows NTLM V1 Elevation of Privilege Vulnerabilitymicrosoft · windows 11 24h2 · CWE-303 | Критическая9,8 | — | 2,2 % | 14 янв. 2025 г. |
39Наблюдать | CVE-2021-32691Эксплойта нет | Auto-merging Person Records Compromisedapollosapp · data-connector-rock · CWE-303 | Критическая9,8 | — | 1,5 % | 16 июн. 2021 г. |
39Наблюдать | CVE-2023-3326Эксплойта нет | Network authentication attack via pam_krb5freebsd · freebsd · CWE-303 | Критическая9,8 | — | 1,1 % | 22 июн. 2023 г. |
39Наблюдать | CVE-2022-20923Эксплойта нет | Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers IPSec VPN Server Authentication Bypass Vulnerabilitycisco · rv110w firmware · CWE-303 | Критическая9,8 | — | 0,9 % | 8 сент. 2022 г. |
39Наблюдать | CVE-2023-29129Эксплойта нет | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatibmendix · saml · CWE-303 | Критическая9,8 | — | 0,9 % | 13 июн. 2023 г. |
39Наблюдать | CVE-2025-66489Эксплойта нет | Cal.com Authentication Bypass via bad TOTP + password checkscal · cal.com · CWE-303 | Критическая9,9 | — | 0,8 % | 3 дек. 2025 г. |
39Наблюдать | CVE-2026-59309Эксплойта нет | vCenter authentication-bypass vulnerabilityvmware · vcenter server · CWE-303 | Критическая9,8 | — | 0,6 % | 30 июл. 2026 г. |
39Наблюдать | CVE-2025-12421Эксплойта нет | Account Takeover via Code Exchange Endpointmattermost · mattermost server · CWE-303 | Критическая9,9 | — | 0,3 % | 27 нояб. 2025 г. |
39Наблюдать | CVE-2025-12419Эксплойта нет | Account takeover on OAuth/OpenID-enabled serversmattermost · mattermost server · CWE-303 | Критическая9,9 | — | 0,3 % | 27 нояб. 2025 г. |
38Наблюдать | CVE-2023-4860Эксплойта нет | Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer procgoogle · chrome · CWE-303 | Критическая9,6 | — | 0,4 % | 16 июл. 2024 г. |
37Наблюдать | CVE-2020-8861Эксплойта нет | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-Fdlink · dap-1330 firmware · CWE-303 | Высокая8,8 | — | 6,5 % | 21 февр. 2020 г. |
37Наблюдать | CVE-2026-29515Эксплойта нет | MiCode FileExplorer SwiFTP Server Authentication Bypassxiaomi · fileexplorer · CWE-303 | Критическая9,3 | — | 1,0 % | 11 мар. 2026 г. |
37Наблюдать | CVE-2024-4332Эксплойта нет | Improper Authentication in Tripwire Enterprise 9.1.0 APIsfortra · tripwire enterprise · CWE-303 | Критическая9,3 | — | 0,6 % | 3 июн. 2024 г. |
36Наблюдать | CVE-2020-15632Эксплойта нет | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers.dlink · dir-842 firmware · CWE-303 | Высокая8,8 | — | 3,3 % | 23 июл. 2020 г. |
36Наблюдать | CVE-2026-28446Эксплойта нет | OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matchingopenclaw · openclaw · CWE-303 | Критическая9,2 | — | 1,0 % | 5 мар. 2026 г. |
36Наблюдать | CVE-2026-41103Эксплойта нет | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerabilitymicrosoft · confluence saml sso · CWE-303 | Критическая9,1 | — | 0,8 % | 12 мая 2026 г. |
36Наблюдать | CVE-2024-10127Эксплойта нет | Support for authentication bypass condition in M-Files LDAP authenticationm-files · m-files server · CWE-303 | Критическая9,2 | — | 0,6 % | 20 нояб. 2024 г. |
36Наблюдать | CVE-2026-3869Эксплойта нет | CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and schneider electric · modicon m580 · CWE-303 | Критическая9,2 | — | 0,5 % | 11 сент. 2026 г. |
36Наблюдать | CVE-2025-14510Эксплойта нет | ABB Ability OPTIMAX Authentication Bypass in Single-Sign Onabb · abb ability optimax · CWE-303 | Критическая9,2 | — | 0,4 % | 16 янв. 2026 г. |
- CVE-2023-2935799Срочно
Microsoft SharePoint Server Elevation of Privilege Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · sharepoint server13 июн. 2023 г.
- CVE-2020-886358В плане
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-867, DIR-878, and DIR-
ВысокаяCVSS 8,8Эксплойта нетEPSS 77 %dlink · dir-878 firmware23 мар. 2020 г.
- CVE-2022-2069546В плане
Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 20 %cisco · wireless lan controller 8.10.151.015 апр. 2022 г.
- CVE-2024-498541В плане
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %github · enterprise server20 мая 2024 г.
- CVE-2018-484140В плане
A vulnerability has been identified in TIM 1531 IRC (All versions < V1.1).
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %siemens · tim 1531 irc firmware29 мар. 2018 г.
- CVE-2025-1339040В плане
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
КритическаяCVSS 9,8Proof of conceptEPSS 5 %wpdirectorykit · wp directory kit3 дек. 2025 г.
- CVE-2025-2131140В плане
Windows NTLM V1 Elevation of Privilege Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %microsoft · windows 11 24h214 янв. 2025 г.
- CVE-2021-3269139Наблюдать
Auto-merging Person Records Compromised
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apollosapp · data-connector-rock16 июн. 2021 г.
- CVE-2023-332639Наблюдать
Network authentication attack via pam_krb5
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %freebsd · freebsd22 июн. 2023 г.
- CVE-2022-2092339Наблюдать
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers IPSec VPN Server Authentication Bypass Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cisco · rv110w firmware8 сент. 2022 г.
- CVE-2023-2912939Наблюдать
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatib
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mendix · saml13 июн. 2023 г.
- CVE-2025-6648939Наблюдать
Cal.com Authentication Bypass via bad TOTP + password checks
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %cal · cal.com3 дек. 2025 г.
- CVE-2026-5930939Наблюдать
vCenter authentication-bypass vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %vmware · vcenter server30 июл. 2026 г.
- CVE-2025-1242139Наблюдать
Account Takeover via Code Exchange Endpoint
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %mattermost · mattermost server27 нояб. 2025 г.
- CVE-2025-1241939Наблюдать
Account takeover on OAuth/OpenID-enabled servers
КритическаяCVSS 9,9Эксплойта нетEPSS 0 %mattermost · mattermost server27 нояб. 2025 г.
- CVE-2023-486038Наблюдать
Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer proc
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %google · chrome16 июл. 2024 г.
- CVE-2020-886137Наблюдать
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DAP-1330 1.10B01 BETA Wi-F
ВысокаяCVSS 8,8Эксплойта нетEPSS 7 %dlink · dap-1330 firmware21 февр. 2020 г.
- CVE-2026-2951537Наблюдать
MiCode FileExplorer SwiFTP Server Authentication Bypass
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %xiaomi · fileexplorer11 мар. 2026 г.
- CVE-2024-433237Наблюдать
Improper Authentication in Tripwire Enterprise 9.1.0 APIs
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %fortra · tripwire enterprise3 июн. 2024 г.
- CVE-2020-1563236Наблюдать
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-842 3.13B05 routers.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %dlink · dir-842 firmware23 июл. 2020 г.
- CVE-2026-2844636Наблюдать
OpenClaw < 2026.2.1 - Inbound Allowlist Policy Bypass in voice-call Extension via Empty Caller ID and Suffix Matching
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %openclaw · openclaw5 мар. 2026 г.
- CVE-2026-4110336Наблюдать
Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %microsoft · confluence saml sso12 мая 2026 г.
- CVE-2024-1012736Наблюдать
Support for authentication bypass condition in M-Files LDAP authentication
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %m-files · m-files server20 нояб. 2024 г.
- CVE-2026-386936Наблюдать
CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %schneider electric · modicon m58011 сент. 2026 г.
- CVE-2025-1451036Наблюдать
ABB Ability OPTIMAX Authentication Bypass in Single-Sign On
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %abb · abb ability optimax16 янв. 2026 г.