CWE-305 · 156 записей
Authentication Bypass by Primary Weakness
CVE этого класса
156 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2025-31161Готовый эксплойт | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instacrushftp · crushftp · CWE-305 | Критическая9,8 | KEV | 100,0 % | 3 апр. 2025 г. |
66На этой неделе | CVE-2026-81578Готовый эксплойт | PaperCut MF/NG: Authentication Bypasspapercut · papercut mf · CWE-305 | Высокая8,8 | KEV | 4,5 % | 28 авг. 2026 г. |
60На этой неделе | CVE-2020-10923Готовый эксплойт | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 rnetgear · r6700 firmware · CWE-305 | Высокая8,8 | — | 84,7 % | 28 июл. 2020 г. |
54В плане | CVE-2023-34124Готовый эксплойт | The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass.sonicwall · analytics · CWE-305 | Критическая9,8 | — | 50,5 % | 12 июл. 2023 г. |
45В плане | CVE-2025-32011Эксплойта нет | KUNBUS Revolution Pi Authentication Bypass by Primary Weaknesskunbus gmbh · revolution pi pictory · CWE-305 | Критическая9,3 | — | 27,5 % | 1 мая 2025 г. |
44В плане | CVE-2022-2651Proof of concept | Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrmjoinbookwyrm · bookwyrm · CWE-305 | Критическая9,8 | — | 15,8 % | 4 авг. 2022 г. |
44В плане | CVE-2023-0777Proof of concept | Authentication Bypass by Primary Weakness in modoboa/modoboamodoboa · modoboa · CWE-305 | Критическая9,8 | — | 15,2 % | 10 февр. 2023 г. |
43В плане | CVE-2023-28126Эксплойта нет | An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploitinivanti · avalanche · CWE-305 | Средняя5,9 | — | 66,7 % | 9 мая 2023 г. |
42В плане | CVE-2021-26102Proof of concept | A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated fortinet · fortiwan · CWE-305 | Критическая9,1 | — | 19,7 % | 19 дек. 2024 г. |
42В плане | CVE-2025-13915Эксплойта нет | Authentication bypass in IBM API Connectibm · api connect · CWE-305 | Критическая9,8 | — | 9,0 % | 26 дек. 2025 г. |
40В плане | CVE-2024-20674Proof of concept | Windows Kerberos Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-305 | Высокая8,8 | — | 17,2 % | 9 янв. 2024 г. |
40В плане | CVE-2022-0547Эксплойта нет | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes uopenvpn · openvpn · CWE-305 | Критическая9,8 | — | 3,6 % | 18 мар. 2022 г. |
40В плане | CVE-2024-1403Proof of concept | Authentication Bypass in OpenEdge Authentication Gateway and AdminServerprogress · openedge · CWE-305 | Критическая9,8 | — | 3,3 % | 27 февр. 2024 г. |
40В плане | CVE-2025-4320Эксплойта нет | Information Disclosure in Birebirsoft's Sufirmambirebirsoft software and technology solutions · sufirmam · CWE-305 | Критическая10,0 | — | 0,5 % | 23 янв. 2026 г. |
39Наблюдать | CVE-2020-24683Эксплойта нет | Authentication Bypass in Symphony Plusabb · symphony \+ historian · CWE-305 | Критическая9,8 | — | 1,5 % | 22 дек. 2020 г. |
39Наблюдать | CVE-2020-15787Эксплойта нет | A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16).siemens · simatic hmi united comfort panels firmware · CWE-305 | Критическая9,8 | — | 1,5 % | 9 сент. 2020 г. |
39Наблюдать | CVE-2021-21403Эксплойта нет | Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/serverkongchuanhujiao project · kongchuanhujiao · CWE-305 | Критическая9,8 | — | 1,4 % | 26 мар. 2021 г. |
39Наблюдать | CVE-2024-50478Proof of concept | WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerabilityswoopnow · 1-click login\ · CWE-305 | Критическая9,8 | — | 1,1 % | 28 окт. 2024 г. |
39Наблюдать | CVE-2023-1307Эксплойта нет | Authentication Bypass by Primary Weakness in froxlor/froxlorfroxlor · froxlor · CWE-305 | Критическая9,8 | — | 1,1 % | 9 мар. 2023 г. |
39Наблюдать | CVE-2023-34137Эксплойта нет | SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authenticatiosonicwall · analytics · CWE-305 | Критическая9,8 | — | 1,0 % | 12 июл. 2023 г. |
39Наблюдать | CVE-2024-1202Эксплойта нет | Authentication Bypass in XPodas' Octopodxpodas · octopod · CWE-305 | Критическая9,8 | — | 0,9 % | 20 мар. 2024 г. |
39Наблюдать | CVE-2026-19349Эксплойта нет | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2CWE-305 | Критическая9,8 | — | 0,8 % | 16 авг. 2026 г. |
39Наблюдать | CVE-2023-1833Эксплойта нет | Authentication Bypass in Redline Routerredline · router firmware · CWE-305 | Критическая9,8 | — | 0,8 % | 14 апр. 2023 г. |
39Наблюдать | CVE-2021-28503Эксплойта нет | In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote atarista · eos · CWE-305 | Критическая9,8 | — | 0,7 % | 4 февр. 2022 г. |
39Наблюдать | CVE-2023-6153Эксплойта нет | Authentication Bypass in TeoSOFT Software TeoBASEteosoft software · teobase · CWE-305 | Критическая9,8 | — | 0,7 % | 27 мар. 2024 г. |
- CVE-2025-3116199Срочно
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy insta
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %crushftp · crushftp3 апр. 2025 г.
- CVE-2026-8157866На этой неделе
PaperCut MF/NG: Authentication Bypass
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 4 %papercut · papercut mf28 авг. 2026 г.
- CVE-2020-1092360На этой неделе
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 r
ВысокаяCVSS 8,8Готовый эксплойтEPSS 85 %netgear · r6700 firmware28 июл. 2020 г.
- CVE-2023-3412454В плане
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass.
КритическаяCVSS 9,8Готовый эксплойтEPSS 50 %sonicwall · analytics12 июл. 2023 г.
- CVE-2025-3201145В плане
KUNBUS Revolution Pi Authentication Bypass by Primary Weakness
КритическаяCVSS 9,3Эксплойта нетEPSS 27 %kunbus gmbh · revolution pi pictory1 мая 2025 г.
- CVE-2022-265144В плане
Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrm
КритическаяCVSS 9,8Proof of conceptEPSS 16 %joinbookwyrm · bookwyrm4 авг. 2022 г.
- CVE-2023-077744В плане
Authentication Bypass by Primary Weakness in modoboa/modoboa
КритическаяCVSS 9,8Proof of conceptEPSS 15 %modoboa · modoboa10 февр. 2023 г.
- CVE-2023-2812643В плане
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploitin
СредняяCVSS 5,9Эксплойта нетEPSS 67 %ivanti · avalanche9 мая 2023 г.
- CVE-2021-2610242В плане
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated
КритическаяCVSS 9,1Proof of conceptEPSS 20 %fortinet · fortiwan19 дек. 2024 г.
- CVE-2025-1391542В плане
Authentication bypass in IBM API Connect
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %ibm · api connect26 дек. 2025 г.
- CVE-2024-2067440В плане
Windows Kerberos Security Feature Bypass Vulnerability
ВысокаяCVSS 8,8Proof of conceptEPSS 17 %microsoft · windows 10 15079 янв. 2024 г.
- CVE-2022-054740В плане
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes u
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %openvpn · openvpn18 мар. 2022 г.
- CVE-2024-140340В плане
Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
КритическаяCVSS 9,8Proof of conceptEPSS 3 %progress · openedge27 февр. 2024 г.
- CVE-2025-432040В плане
Information Disclosure in Birebirsoft's Sufirmam
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %birebirsoft software and technology solutions · sufirmam23 янв. 2026 г.
- CVE-2020-2468339Наблюдать
Authentication Bypass in Symphony Plus
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · symphony \+ historian22 дек. 2020 г.
- CVE-2020-1578739Наблюдать
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %siemens · simatic hmi united comfort panels firmware9 сент. 2020 г.
- CVE-2021-2140339Наблюдать
Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/server
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %kongchuanhujiao project · kongchuanhujiao26 мар. 2021 г.
- CVE-2024-5047839Наблюдать
WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 1 %swoopnow · 1-click login\28 окт. 2024 г.
- CVE-2023-130739Наблюдать
Authentication Bypass by Primary Weakness in froxlor/froxlor
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %froxlor · froxlor9 мар. 2023 г.
- CVE-2023-3413739Наблюдать
SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authenticatio
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sonicwall · analytics12 июл. 2023 г.
- CVE-2024-120239Наблюдать
Authentication Bypass in XPodas' Octopod
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %xpodas · octopod20 мар. 2024 г.
- CVE-2026-1934939Наблюдать
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %16 авг. 2026 г.
- CVE-2023-183339Наблюдать
Authentication Bypass in Redline Router
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redline · router firmware14 апр. 2023 г.
- CVE-2021-2850339Наблюдать
In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote at
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %arista · eos4 февр. 2022 г.
- CVE-2023-615339Наблюдать
Authentication Bypass in TeoSOFT Software TeoBASE
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %teosoft software · teobase27 мар. 2024 г.