CWE-1390 · 85 kayıt
Weak Authentication
Bu sınıftaki CVE’ler
85 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
71Bu hafta | CVE-2026-55040Silahlaştırılmış | Microsoft SharePoint Server Security Feature Bypass Vulnerabilitymicrosoft · sharepoint server · CWE-1390 | Kritik9,1 | KEV | %17,5 | 14 Tem 2026 |
57Planlayın | CVE-2025-40554Kavram kanıtı | SolarWinds Web Help Desk Authentication Bypass Vulnerabilitysolarwinds · web help desk · CWE-1390 | Kritik9,8 | — | %60,6 | 28 Oca 2026 |
55Planlayın | CVE-2025-40552Kavram kanıtı | SolarWinds Web Help Desk Authentication Bypass Vulnerabilitysolarwinds · web help desk · CWE-1390 | Kritik9,8 | — | %52,0 | 28 Oca 2026 |
40Planlayın | CVE-2025-30411İstismar yok | Sensitive data disclosure and manipulation due to improper authentication.acronis · cyber protect · CWE-1390 | Kritik10,0 | — | %0,8 | 19 Şub 2026 |
40Planlayın | CVE-2025-30412İstismar yok | Sensitive data disclosure and manipulation due to improper authentication.acronis · cyber protect · CWE-1390 | Kritik10,0 | — | %0,7 | 19 Şub 2026 |
39İzleyin | CVE-2026-65098İstismar yok | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.nvidia · nemoclaw · CWE-1390 | Kritik9,8 | — | %1,0 | 25 Ağu 2026 |
39İzleyin | CVE-2022-43400İstismar yok | A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)).siemens · siveillance video mobile server · CWE-1390 | Kritik9,8 | — | %1,0 | 21 Eki 2022 |
39İzleyin | CVE-2026-73025İstismar yok | Windows iSCSI Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-1390 | Kritik9,8 | — | %0,9 | 8 Eyl 2026 |
39İzleyin | CVE-2024-38182İstismar yok | Microsoft Dynamics 365 Elevation of Privilege Vulnerabilitymicrosoft · dynamics 365 · CWE-1390 | Kritik9,8 | — | %0,9 | 31 Tem 2024 |
39İzleyin | CVE-2026-28710İstismar yok | Sensitive information disclosure and manipulation due to improper authentication.acronis · cyber protect · CWE-1390 | Kritik9,8 | — | %0,6 | 5 Mar 2026 |
39İzleyin | CVE-2025-39596Kavram kanıtı | WordPress Quentn WP plugin <= 1.2.8 - Privilege Escalation Vulnerabilityquentn.com gmbh · quentn wp · CWE-1390 | Kritik9,8 | — | %0,6 | 17 Nis 2025 |
39İzleyin | CVE-2025-1387İstismar yok | Learning Digital Orca HCM - Improper Authenticationlearningdigital · orca hcm · CWE-1390 | Kritik9,8 | — | %0,6 | 17 Şub 2025 |
39İzleyin | CVE-2025-49201İstismar yok | A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all vefortinet · fortipam · CWE-1390 | Kritik9,8 | — | %0,6 | 14 Eki 2025 |
39İzleyin | CVE-2024-50563İstismar yok | A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud vfortinet · fortianalyzer · CWE-1390 | Kritik9,8 | — | %0,6 | 16 Oca 2025 |
39İzleyin | CVE-2024-13239İstismar yok | Two-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2024-003two-factor authentication project · two-factor authentication · CWE-1390 | Kritik9,8 | — | %0,6 | 9 Oca 2025 |
39İzleyin | CVE-2024-48886İstismar yok | A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, Forfortinet · fortianalyzer · CWE-1390 | Kritik9,8 | — | %0,5 | 14 Oca 2025 |
39İzleyin | CVE-2025-47479İstismar yok | WordPress WP Compress plugin <= 6.30.30 - Broken Authentication Vulnerabilitywpcompress · wp compress · CWE-1390 | Kritik9,8 | — | %0,4 | 4 Tem 2025 |
37İzleyin | CVE-2026-6886İstismar yok | BorG Technology Corporation|Borg SPM 2007 - Authentication Bypassborg technology corporation · borg spm 2007 · CWE-1390 | Kritik9,3 | — | %0,8 | 23 Nis 2026 |
37İzleyin | CVE-2024-54092İstismar yok | A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (Alsiemens · industrial edge device kit - arm64 v1.17 · CWE-1390 | Kritik9,3 | — | %0,7 | 8 Nis 2025 |
37İzleyin | CVE-2023-53894İstismar yok | phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerabilitydulldusk · phpfilemanager · CWE-1390 | Kritik9,3 | — | %0,6 | 16 Ara 2025 |
37İzleyin | CVE-2025-12870İstismar yok | aEnrich|eHRD - Authentication Abuseaenrich · a\+hrd · CWE-1390 | Kritik9,3 | — | %0,6 | 12 Kas 2025 |
37İzleyin | CVE-2025-12871İstismar yok | aEnrich|a+HRD - Authentication Abuseaenrich · a\+hrd · CWE-1390 | Kritik9,3 | — | %0,6 | 12 Kas 2025 |
37İzleyin | CVE-2026-73819İstismar yok | Ebyte NA111-M Weak Authenticationebyte · ebyte na111-m firmware · CWE-1390 | Kritik9,3 | — | %0,5 | 31 Ağu 2026 |
37İzleyin | CVE-2026-68067İstismar yok | Mira Hormone Monitor, Mira Android App Weak Authenticationquanovate tech inc. (operating as mira / mira care) · mira firmware · CWE-1390 | Kritik9,3 | — | %0,5 | 11 Ağu 2026 |
37İzleyin | CVE-2024-45367İstismar yok | Optigo Networks ONS-S8 Spectra Aggregation Switch Weak Authenticationoptigo networks · ons-s8 spectra aggregation switch · CWE-1390 | Kritik9,3 | — | %0,5 | 3 Eki 2024 |
- CVE-2026-5504071Bu hafta
Microsoft SharePoint Server Security Feature Bypass Vulnerability
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %18microsoft · sharepoint server14 Tem 2026
- CVE-2025-4055457Planlayın
SolarWinds Web Help Desk Authentication Bypass Vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %61solarwinds · web help desk28 Oca 2026
- CVE-2025-4055255Planlayın
SolarWinds Web Help Desk Authentication Bypass Vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %52solarwinds · web help desk28 Oca 2026
- CVE-2025-3041140Planlayın
Sensitive data disclosure and manipulation due to improper authentication.
KritikCVSS 10,0İstismar yokEPSS %1acronis · cyber protect19 Şub 2026
- CVE-2025-3041240Planlayın
Sensitive data disclosure and manipulation due to improper authentication.
KritikCVSS 10,0İstismar yokEPSS %1acronis · cyber protect19 Şub 2026
- CVE-2026-6509839İzleyin
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.
KritikCVSS 9,8İstismar yokEPSS %1nvidia · nemoclaw25 Ağu 2026
- CVE-2022-4340039İzleyin
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)).
KritikCVSS 9,8İstismar yokEPSS %1siemens · siveillance video mobile server21 Eki 2022
- CVE-2026-7302539İzleyin
Windows iSCSI Security Feature Bypass Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1microsoft · windows 10 16078 Eyl 2026
- CVE-2024-3818239İzleyin
Microsoft Dynamics 365 Elevation of Privilege Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1microsoft · dynamics 36531 Tem 2024
- CVE-2026-2871039İzleyin
Sensitive information disclosure and manipulation due to improper authentication.
KritikCVSS 9,8İstismar yokEPSS %1acronis · cyber protect5 Mar 2026
- CVE-2025-3959639İzleyin
WordPress Quentn WP plugin <= 1.2.8 - Privilege Escalation Vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %1quentn.com gmbh · quentn wp17 Nis 2025
- CVE-2025-138739İzleyin
Learning Digital Orca HCM - Improper Authentication
KritikCVSS 9,8İstismar yokEPSS %1learningdigital · orca hcm17 Şub 2025
- CVE-2025-4920139İzleyin
A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all ve
KritikCVSS 9,8İstismar yokEPSS %1fortinet · fortipam14 Eki 2025
- CVE-2024-5056339İzleyin
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud v
KritikCVSS 9,8İstismar yokEPSS %1fortinet · fortianalyzer16 Oca 2025
- CVE-2024-1323939İzleyin
Two-factor Authentication (TFA) - Moderately critical - Access bypass - SA-CONTRIB-2024-003
KritikCVSS 9,8İstismar yokEPSS %1two-factor authentication project · two-factor authentication9 Oca 2025
- CVE-2024-4888639İzleyin
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, For
KritikCVSS 9,8İstismar yokEPSS %0fortinet · fortianalyzer14 Oca 2025
- CVE-2025-4747939İzleyin
WordPress WP Compress plugin <= 6.30.30 - Broken Authentication Vulnerability
KritikCVSS 9,8İstismar yokEPSS %0wpcompress · wp compress4 Tem 2025
- CVE-2026-688637İzleyin
BorG Technology Corporation|Borg SPM 2007 - Authentication Bypass
KritikCVSS 9,3İstismar yokEPSS %1borg technology corporation · borg spm 200723 Nis 2026
- CVE-2024-5409237İzleyin
A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (Al
KritikCVSS 9,3İstismar yokEPSS %1siemens · industrial edge device kit - arm64 v1.178 Nis 2025
- CVE-2023-5389437İzleyin
phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability
KritikCVSS 9,3İstismar yokEPSS %1dulldusk · phpfilemanager16 Ara 2025
- CVE-2025-1287037İzleyin
aEnrich|eHRD - Authentication Abuse
KritikCVSS 9,3İstismar yokEPSS %1aenrich · a\+hrd12 Kas 2025
- CVE-2025-1287137İzleyin
aEnrich|a+HRD - Authentication Abuse
KritikCVSS 9,3İstismar yokEPSS %1aenrich · a\+hrd12 Kas 2025
- CVE-2026-7381937İzleyin
Ebyte NA111-M Weak Authentication
KritikCVSS 9,3İstismar yokEPSS %1ebyte · ebyte na111-m firmware31 Ağu 2026
- CVE-2026-6806737İzleyin
Mira Hormone Monitor, Mira Android App Weak Authentication
KritikCVSS 9,3İstismar yokEPSS %1quanovate tech inc. (operating as mira / mira care) · mira firmware11 Ağu 2026
- CVE-2024-4536737İzleyin
Optigo Networks ONS-S8 Spectra Aggregation Switch Weak Authentication
KritikCVSS 9,3İstismar yokEPSS %1optigo networks · ons-s8 spectra aggregation switch3 Eki 2024