Перейти к содержимому
Noroxi

CWE-592 · 21 записей

DEPRECATED: Authentication Bypass Issues

CVE этого класса

21 записей

  • CVE-2018-10933
    64На этой неделе

    A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4.

    КритическаяCVSS 9,1Готовый эксплойтEPSS 92 %

    libssh · libssh17 окт. 2018 г.

  • CVE-2018-14643
    41В плане

    An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman.

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    theforeman · foreman21 сент. 2018 г.

  • CVE-2014-5432
    40В плане

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    baxter · sigma spectrum infusion system firmware26 мар. 2019 г.

  • CVE-2018-1085
    40В плане

    openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    redhat · openshift container platform15 июн. 2018 г.

  • CVE-2019-3899
    39Наблюдать

    It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misus

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    redhat · openshift container platform22 апр. 2019 г.

  • CVE-2026-43512
    39Наблюдать

    Apache Tomcat: Digest authenticator will authenticate any unknown user

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    apache · tomcat12 мая 2026 г.

  • CVE-2017-2684
    37Наблюдать

    Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access

    КритическаяCVSS 9,0Эксплойта нетEPSS 2 %

    siemens · simatic logon21 февр. 2017 г.

  • CVE-2018-10847
    35Наблюдать

    prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    prosody · prosody30 июл. 2018 г.

  • CVE-2019-14843
    35Наблюдать

    A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    redhat · single sign-on7 янв. 2020 г.

  • CVE-2017-2650
    34Наблюдать

    It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM comm

    ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %

    jenkins · pipeline classpath step27 июл. 2018 г.

  • CVE-2016-8371
    32Наблюдать

    The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

    ВысокаяCVSS 7,3Proof of conceptEPSS 11 %

    phoenixcontact · ilc plcs firmware5 апр. 2018 г.

  • CVE-2019-10201
    32Наблюдать

    It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    redhat · keycloak14 авг. 2019 г.

  • CVE-2012-4688
    30Наблюдать

    I-GEN opLYNX Central Authentication Bypass

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    i-gen · oplynx31 дек. 2012 г.

  • CVE-2017-7537
    30Наблюдать

    It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package befor

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    redhat · enterprise linux desktop26 июл. 2018 г.

  • CVE-2017-7536
    28Наблюдать

    In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, whi

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    redhat · hibernate validator10 янв. 2018 г.

  • CVE-2023-30971
    27Наблюдать

    Gaia unauthenticated endpoints

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    palantir · com.palantir.acme.gaia:gaia19 дек. 2025 г.

  • CVE-2019-10198
    26Наблюдать

    An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7.

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    theforeman · foreman-tasks31 июл. 2019 г.

  • CVE-2017-12164
    25Наблюдать

    A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin.

    СредняяCVSS 6,4Эксплойта нетEPSS 0 %

    gnome · gnome display manager26 июл. 2018 г.

  • CVE-2024-42759
    25Наблюдать

    An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    ellevo · ellevo9 сент. 2024 г.

  • CVE-2016-8616
    24Наблюдать

    A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and pass

    СредняяCVSS 5,9Эксплойта нетEPSS 3 %

    haxx · curl1 авг. 2018 г.

  • CVE-2014-2367
    17Наблюдать

    Advantech WebAccess Authentication Bypass Issues

    СредняяCVSS 4,3Эксплойта нетEPSS 2 %

    advantech · advantech webaccess19 июл. 2014 г.

Все классы уязвимостей