CWE-294 · 269 kayıt
Authentication Bypass by Capture-replay
Bu sınıftaki CVE’ler
269 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2017-3191İstismar yok | D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.d-link · dir-130 firmware · CWE-294 | Kritik9,8 | — | %62,5 | 15 Ara 2017 |
52Planlayın | CVE-2023-49231İstismar yok | An authentication bypass vulnerability was found in Stilog Visual Planning 8.CWE-294 | Kritik9,8 | — | %42,9 | 29 Mar 2024 |
43Planlayın | CVE-2022-22806İstismar yok | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malschneider-electric · smt series 1015 ups firmware · CWE-294 | Kritik9,8 | — | %12,5 | 9 Mar 2022 |
41Planlayın | CVE-2017-6034İstismar yok | Schneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replayschneider-electric · modbus firmware · CWE-294 | Kritik9,8 | — | %5,2 | 29 Haz 2017 |
40Planlayın | CVE-2018-7790İstismar yok | An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to firschneider-electric · modicon m221 firmware · CWE-294 | Kritik9,8 | — | %2,5 | 29 Ağu 2018 |
40Planlayın | CVE-2025-49752İstismar yok | Azure Bastion Elevation of Privilege Vulnerabilitymicrosoft · azure bastion developer · CWE-294 | Kritik10,0 | — | %0,9 | 20 Kas 2025 |
39İzleyin | CVE-2023-30909İstismar yok | A remote authentication bypass issue exists in some OneView APIs.hp · oneview · CWE-294 | Kritik9,8 | — | %1,5 | 14 Eyl 2023 |
39İzleyin | CVE-2018-17932İstismar yok | JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, whicjuuko · k-800 firmware · CWE-294 | Kritik9,8 | — | %1,5 | 2 Kas 2020 |
39İzleyin | CVE-2018-19025İstismar yok | In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmwarejuuko · k-808 firmware · CWE-294 | Kritik9,8 | — | %1,5 | 2 Kas 2020 |
39İzleyin | CVE-2022-45789İstismar yok | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the cschneider-electric · ecostruxure control expert · CWE-294 | Kritik9,8 | — | %1,5 | 31 Oca 2023 |
39İzleyin | CVE-2019-18226İstismar yok | Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras andhoneywell · h2w2pc1m firmware · CWE-294 | Kritik9,8 | — | %1,4 | 31 Eki 2019 |
39İzleyin | CVE-2022-37011İstismar yok | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All vemendix · saml · CWE-294 | Kritik9,8 | — | %1,2 | 13 Eyl 2022 |
39İzleyin | CVE-2022-29334İstismar yok | An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.h project · h · CWE-294 | Kritik9,8 | — | %1,2 | 24 May 2022 |
39İzleyin | CVE-2021-38459İstismar yok | The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level.auvesy · versiondog · CWE-294 | Kritik9,8 | — | %1,0 | 22 Eki 2021 |
39İzleyin | CVE-2023-1886İstismar yok | Authentication Bypass by Capture-replay in thorsten/phpmyfaqphpmyfaq · phpmyfaq · CWE-294 | Kritik9,8 | — | %0,9 | 5 Nis 2023 |
39İzleyin | CVE-2022-36089İstismar yok | VelaUX APIServer vulnerable to Authentication Bypass by Capture-replaykubevela · kubevela · CWE-294 | Kritik9,8 | — | %0,9 | 7 Eyl 2022 |
39İzleyin | CVE-2023-1537İstismar yok | Authentication Bypass by Capture-replay in answerdev/answeranswer · answer · CWE-294 | Kritik9,8 | — | %0,8 | 21 Mar 2023 |
39İzleyin | CVE-2021-22640İstismar yok | Ovarro TBox Insufficiently Protected Credentialsovarro · twinsoft · CWE-294 | Kritik9,8 | — | %0,8 | 28 Tem 2022 |
39İzleyin | CVE-2026-65905İstismar yok | Apache Tomcat: Limited replay attack possible with DIGEST authenticationapache · tomcat · CWE-294 | Kritik9,8 | — | %0,8 | 25 Ağu 2026 |
39İzleyin | CVE-2022-44457İstismar yok | A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All vemendix · saml · CWE-294 | Kritik9,8 | — | %0,7 | 8 Kas 2022 |
39İzleyin | CVE-2023-0014İstismar yok | Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platformsap · netweaver application server abap · CWE-294 | Kritik9,8 | — | %0,7 | 10 Oca 2023 |
39İzleyin | CVE-2026-11856İstismar yok | cross-origin Digest auth state leakhaxx · curl · CWE-294 | Kritik9,8 | — | %0,7 | 3 Tem 2026 |
39İzleyin | CVE-2026-28564İstismar yok | Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentialsapache software foundation · apache iotdb · CWE-294 | Kritik9,8 | — | %0,7 | 10 Tem 2026 |
39İzleyin | CVE-2026-68079İstismar yok | Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replayapache · cxf · CWE-294 | Kritik9,8 | — | %0,7 | 6 Ağu 2026 |
39İzleyin | CVE-2024-38438İstismar yok | D-Link - CWE-294: Authentication Bypass by Capture-replaydlink · dsl-225 firmware · CWE-294 | Kritik9,8 | — | %0,7 | 21 Tem 2024 |
- CVE-2017-319158Planlayın
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page.
KritikCVSS 9,8İstismar yokEPSS %63d-link · dir-130 firmware15 Ara 2017
- CVE-2023-4923152Planlayın
An authentication bypass vulnerability was found in Stilog Visual Planning 8.
KritikCVSS 9,8İstismar yokEPSS %4329 Mar 2024
- CVE-2022-2280643Planlayın
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a mal
KritikCVSS 9,8İstismar yokEPSS %12schneider-electric · smt series 1015 ups firmware9 Mar 2022
- CVE-2017-603441Planlayın
Schneider Electric Modicon Modbus Protocol Authentication Bypass by Capture-replay
KritikCVSS 9,8İstismar yokEPSS %5schneider-electric · modbus firmware29 Haz 2017
- CVE-2018-779040Planlayın
An Information Management Error vulnerability exists in Schneider Electric's Modicon M221 product (all references, all versions prior to fir
KritikCVSS 9,8İstismar yokEPSS %2schneider-electric · modicon m221 firmware29 Ağu 2018
- CVE-2025-4975240Planlayın
Azure Bastion Elevation of Privilege Vulnerability
KritikCVSS 10,0İstismar yokEPSS %1microsoft · azure bastion developer20 Kas 2025
- CVE-2023-3090939İzleyin
A remote authentication bypass issue exists in some OneView APIs.
KritikCVSS 9,8İstismar yokEPSS %2hp · oneview14 Eyl 2023
- CVE-2018-1793239İzleyin
JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, whic
KritikCVSS 9,8İstismar yokEPSS %2juuko · k-800 firmware2 Kas 2020
- CVE-2018-1902539İzleyin
In JUUKO K-808, an attacker could specially craft a packet that encodes an arbitrary command, which could be executed on the K-808 (Firmware
KritikCVSS 9,8İstismar yokEPSS %2juuko · k-808 firmware2 Kas 2020
- CVE-2022-4578939İzleyin
A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the c
KritikCVSS 9,8İstismar yokEPSS %1schneider-electric · ecostruxure control expert31 Oca 2023
- CVE-2019-1822639İzleyin
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and
KritikCVSS 9,8İstismar yokEPSS %1honeywell · h2w2pc1m firmware31 Eki 2019
- CVE-2022-3701139İzleyin
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All ve
KritikCVSS 9,8İstismar yokEPSS %1mendix · saml13 Eyl 2022
- CVE-2022-2933439İzleyin
An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.
KritikCVSS 9,8İstismar yokEPSS %1h project · h24 May 2022
- CVE-2021-3845939İzleyin
The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level.
KritikCVSS 9,8İstismar yokEPSS %1auvesy · versiondog22 Eki 2021
- CVE-2023-188639İzleyin
Authentication Bypass by Capture-replay in thorsten/phpmyfaq
KritikCVSS 9,8İstismar yokEPSS %1phpmyfaq · phpmyfaq5 Nis 2023
- CVE-2022-3608939İzleyin
VelaUX APIServer vulnerable to Authentication Bypass by Capture-replay
KritikCVSS 9,8İstismar yokEPSS %1kubevela · kubevela7 Eyl 2022
- CVE-2023-153739İzleyin
Authentication Bypass by Capture-replay in answerdev/answer
KritikCVSS 9,8İstismar yokEPSS %1answer · answer21 Mar 2023
- CVE-2021-2264039İzleyin
Ovarro TBox Insufficiently Protected Credentials
KritikCVSS 9,8İstismar yokEPSS %1ovarro · twinsoft28 Tem 2022
- CVE-2026-6590539İzleyin
Apache Tomcat: Limited replay attack possible with DIGEST authentication
KritikCVSS 9,8İstismar yokEPSS %1apache · tomcat25 Ağu 2026
- CVE-2022-4445739İzleyin
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All ve
KritikCVSS 9,8İstismar yokEPSS %1mendix · saml8 Kas 2022
- CVE-2023-001439İzleyin
Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
KritikCVSS 9,8İstismar yokEPSS %1sap · netweaver application server abap10 Oca 2023
- CVE-2026-1185639İzleyin
cross-origin Digest auth state leak
KritikCVSS 9,8İstismar yokEPSS %1haxx · curl3 Tem 2026
- CVE-2026-2856439İzleyin
Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials
KritikCVSS 9,8İstismar yokEPSS %1apache software foundation · apache iotdb10 Tem 2026
- CVE-2026-6807939İzleyin
Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay
KritikCVSS 9,8İstismar yokEPSS %1apache · cxf6 Ağu 2026
- CVE-2024-3843839İzleyin
D-Link - CWE-294: Authentication Bypass by Capture-replay
KritikCVSS 9,8İstismar yokEPSS %1dlink · dsl-225 firmware21 Tem 2024