CWE-304 · 35 записей
Missing Critical Step in Authentication
CVE этого класса
37 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-2302Эксплойта нет | LENZE: Missing password verification in authorisation procedurelenze · c520 firmware · CWE-304 | Критическая9,8 | — | 2,1 % | 11 июл. 2022 г. |
40В плане | CVE-2024-2172Эксплойта нет | Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalationcyberlord92 · web application firewall – website security · CWE-304 | Критическая9,8 | — | 1,7 % | 13 мар. 2024 г. |
39Наблюдать | CVE-2011-3172Эксплойта нет | unix2_chkpwd do not check for a valid accountsuse · suse linux enterprise server · CWE-304 | Критическая9,8 | — | 1,0 % | 8 июн. 2018 г. |
39Наблюдать | CVE-2024-8954Эксплойта нет | Authentication Bypass in composiohq/composiocomposio · composio · CWE-304 | Критическая9,8 | — | 0,9 % | 20 мар. 2025 г. |
39Наблюдать | CVE-2025-24322Эксплойта нет | An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110.tenda · ac6 firmware · CWE-304 | Критическая9,8 | — | 0,6 % | 20 авг. 2025 г. |
39Наблюдать | CVE-2024-45764Эксплойта нет | Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability.dell · enterprise sonic distribution · CWE-304 | Критическая9,8 | — | 0,5 % | 8 нояб. 2024 г. |
38Наблюдать | CVE-2023-54391Proof of concept | Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameterproxmox server solutions gmbh · proxmox virtual environment (ve) · CWE-304 | Критическая9,3 | — | 3,0 % | 1 сент. 2026 г. |
36Наблюдать | CVE-2022-1065Эксплойта нет | Multi Factor Authentication Bypass in various versions of Abacus ERPabacus · abacus erp 2018 · CWE-304 | Высокая8,8 | — | 2,9 % | 19 апр. 2022 г. |
36Наблюдать | CVE-2026-61466Эксплойта нет | Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalationapache · cxf · CWE-304 | Критическая9,1 | — | 0,7 % | 6 авг. 2026 г. |
36Наблюдать | CVE-2026-59564Эксплойта нет | Authentication bypass between ZCC and client connector portalzscaler · client connector · CWE-304 | Критическая9,1 | — | 0,5 % | 24 авг. 2026 г. |
36Наблюдать | CVE-2026-94052Эксплойта нет | Apache MINA SSHD: LDAP password authentication ineffectiveapache software foundation · apache mina sshd · CWE-304 | Критическая9,1 | — | — | Сегодня |
35Наблюдать | CVE-2022-40622Эксплойта нет | WAVLINK Quantum D4G (WN531G3) Session Management by IP Addresswavlink · wn531g3 firmware · CWE-304 | Высокая8,8 | — | 0,7 % | 13 сент. 2022 г. |
35Наблюдать | CVE-2024-12048Эксплойта нет | IDOR Vulnerability in transformeroptimus/superagisuperagi · superagi · CWE-304 | Высокая8,8 | — | 0,7 % | 20 мар. 2025 г. |
34Наблюдать | CVE-2026-67351Эксплойта нет | Serendipity < 2.6.1 Authentication Bypass via Username Collisions9y · serendipity · CWE-304 | Высокая8,7 | — | 0,6 % | 30 июл. 2026 г. |
34Наблюдать | CVE-2026-76207Эксплойта нет | phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookiephpmyfaq · phpmyfaq · CWE-304 | Высокая8,6 | — | 0,5 % | 19 авг. 2026 г. |
32Наблюдать | CVE-2024-9216Эксплойта нет | Authentication Bypass in gaizhenbiao/ChuanhuChatGPTgaizhenbiao · chuanhuchatgpt · CWE-304 | Высокая8,1 | — | 0,6 % | 20 мар. 2025 г. |
32Наблюдать | CVE-2026-42452Эксплойта нет | Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTPtermix-ssh · termix · CWE-304 | Высокая8,1 | — | 0,4 % | 8 мая 2026 г. |
32Наблюдать | CVE-2024-11302Эксплойта нет | Missing check_access in lollms_binding_infos in parisneo/lollmsparisneo · parisneo/lollms · CWE-304 | Высокая8,0 | — | 0,2 % | 20 мар. 2025 г. |
32Наблюдать | CVE-2026-93994Эксплойта нет | Apache MINA SSHD: Repeated-publickey policy bypass on serverapache software foundation · apache mina sshd · CWE-304 | Высокая8,1 | — | — | Сегодня |
31Наблюдать | CVE-2024-12136Эксплойта нет | Improper Access Control in Elfatek Elektronics' ANKA JPD-00028elfatek · anka jpd00028 firmware · CWE-304 | Высокая7,8 | — | 0,2 % | 19 мар. 2025 г. |
30Наблюдать | CVE-2026-55957Proof of concept | Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bindapache · tomcat · CWE-304 | Высокая7,3 | — | 2,9 % | 29 июн. 2026 г. |
30Наблюдать | CVE-2022-2821Эксплойта нет | Missing Critical Step in Authentication in namelessmc/namelessnamelessmc · nameless · CWE-304 | Высокая7,5 | — | 1,3 % | 15 авг. 2022 г. |
30Наблюдать | CVE-2024-20153Эксплойта нет | In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID.linuxfoundation · yocto · CWE-304 | Высокая7,5 | — | 0,3 % | 6 янв. 2025 г. |
29Наблюдать | CVE-2023-52424Эксплойта нет | The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WECWE-304 | Высокая7,4 | — | 0,7 % | 17 мая 2024 г. |
29Наблюдать | CVE-2026-40542Эксплойта нет | Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verificationapache · httpclient · CWE-304 | Высокая7,3 | — | 0,7 % | 22 апр. 2026 г. |
- CVE-2022-230240В плане
LENZE: Missing password verification in authorisation procedure
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lenze · c520 firmware11 июл. 2022 г.
- CVE-2024-217240В плане
Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cyberlord92 · web application firewall – website security13 мар. 2024 г.
- CVE-2011-317239Наблюдать
unix2_chkpwd do not check for a valid account
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %suse · suse linux enterprise server8 июн. 2018 г.
- CVE-2024-895439Наблюдать
Authentication Bypass in composiohq/composio
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %composio · composio20 мар. 2025 г.
- CVE-2025-2432239Наблюдать
An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tenda · ac6 firmware20 авг. 2025 г.
- CVE-2024-4576439Наблюдать
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · enterprise sonic distribution8 нояб. 2024 г.
- CVE-2023-5439138Наблюдать
Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
КритическаяCVSS 9,3Proof of conceptEPSS 3 %proxmox server solutions gmbh · proxmox virtual environment (ve)1 сент. 2026 г.
- CVE-2022-106536Наблюдать
Multi Factor Authentication Bypass in various versions of Abacus ERP
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %abacus · abacus erp 201819 апр. 2022 г.
- CVE-2026-6146636Наблюдать
Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %apache · cxf6 авг. 2026 г.
- CVE-2026-5956436Наблюдать
Authentication bypass between ZCC and client connector portal
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %zscaler · client connector24 авг. 2026 г.
- CVE-2026-9405236Наблюдать
Apache MINA SSHD: LDAP password authentication ineffective
КритическаяCVSS 9,1Эксплойта нетapache software foundation · apache mina sshdСегодня
- CVE-2022-4062235Наблюдать
WAVLINK Quantum D4G (WN531G3) Session Management by IP Address
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wavlink · wn531g3 firmware13 сент. 2022 г.
- CVE-2024-1204835Наблюдать
IDOR Vulnerability in transformeroptimus/superagi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %superagi · superagi20 мар. 2025 г.
- CVE-2026-6735134Наблюдать
Serendipity < 2.6.1 Authentication Bypass via Username Collision
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %s9y · serendipity30 июл. 2026 г.
- CVE-2026-7620734Наблюдать
phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %phpmyfaq · phpmyfaq19 авг. 2026 г.
- CVE-2024-921632Наблюдать
Authentication Bypass in gaizhenbiao/ChuanhuChatGPT
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %gaizhenbiao · chuanhuchatgpt20 мар. 2025 г.
- CVE-2026-4245232Наблюдать
Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTP
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %termix-ssh · termix8 мая 2026 г.
- CVE-2024-1130232Наблюдать
Missing check_access in lollms_binding_infos in parisneo/lollms
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %parisneo · parisneo/lollms20 мар. 2025 г.
- CVE-2026-9399432Наблюдать
Apache MINA SSHD: Repeated-publickey policy bypass on server
ВысокаяCVSS 8,1Эксплойта нетapache software foundation · apache mina sshdСегодня
- CVE-2024-1213631Наблюдать
Improper Access Control in Elfatek Elektronics' ANKA JPD-00028
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %elfatek · anka jpd00028 firmware19 мар. 2025 г.
- CVE-2026-5595730Наблюдать
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
ВысокаяCVSS 7,3Proof of conceptEPSS 3 %apache · tomcat29 июн. 2026 г.
- CVE-2022-282130Наблюдать
Missing Critical Step in Authentication in namelessmc/nameless
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %namelessmc · nameless15 авг. 2022 г.
- CVE-2024-2015330Наблюдать
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %linuxfoundation · yocto6 янв. 2025 г.
- CVE-2023-5242429Наблюдать
The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WE
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %17 мая 2024 г.
- CVE-2026-4054229Наблюдать
Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %apache · httpclient22 апр. 2026 г.