İçeriğe atla
Noroxi

CWE-304 · 35 kayıt

Missing Critical Step in Authentication

Bu sınıftaki CVE’ler

37 kayıt

  • CVE-2022-2302
    40Planlayın

    LENZE: Missing password verification in authorisation procedure

    KritikCVSS 9,8İstismar yokEPSS %2

    lenze · c520 firmware11 Tem 2022

  • CVE-2024-2172
    40Planlayın

    Malware Scanner <= 4.7.2 and Web Application Firewall <= 2.1.1 - Unauthenticated Privilege Escalation

    KritikCVSS 9,8İstismar yokEPSS %2

    cyberlord92 · web application firewall – website security13 Mar 2024

  • CVE-2011-3172
    39İzleyin

    unix2_chkpwd do not check for a valid account

    KritikCVSS 9,8İstismar yokEPSS %1

    suse · suse linux enterprise server8 Haz 2018

  • CVE-2024-8954
    39İzleyin

    Authentication Bypass in composiohq/composio

    KritikCVSS 9,8İstismar yokEPSS %1

    composio · composio20 Mar 2025

  • CVE-2025-24322
    39İzleyin

    An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110.

    KritikCVSS 9,8İstismar yokEPSS %1

    tenda · ac6 firmware20 Ağu 2025

  • CVE-2024-45764
    39İzleyin

    Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %1

    dell · enterprise sonic distribution8 Kas 2024

  • CVE-2023-54391
    38İzleyin

    Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter

    KritikCVSS 9,3Kavram kanıtıEPSS %3

    proxmox server solutions gmbh · proxmox virtual environment (ve)1 Eyl 2026

  • CVE-2022-1065
    36İzleyin

    Multi Factor Authentication Bypass in various versions of Abacus ERP

    YüksekCVSS 8,8İstismar yokEPSS %3

    abacus · abacus erp 201819 Nis 2022

  • CVE-2026-61466
    36İzleyin

    Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation

    KritikCVSS 9,1İstismar yokEPSS %1

    apache · cxf6 Ağu 2026

  • CVE-2026-59564
    36İzleyin

    Authentication bypass between ZCC and client connector portal

    KritikCVSS 9,1İstismar yokEPSS %1

    zscaler · client connector24 Ağu 2026

  • CVE-2026-94052
    36İzleyin

    Apache MINA SSHD: LDAP password authentication ineffective

    KritikCVSS 9,1İstismar yok

    apache software foundation · apache mina sshdBugün

  • CVE-2022-40622
    35İzleyin

    WAVLINK Quantum D4G (WN531G3) Session Management by IP Address

    YüksekCVSS 8,8İstismar yokEPSS %1

    wavlink · wn531g3 firmware13 Eyl 2022

  • CVE-2024-12048
    35İzleyin

    IDOR Vulnerability in transformeroptimus/superagi

    YüksekCVSS 8,8İstismar yokEPSS %1

    superagi · superagi20 Mar 2025

  • CVE-2026-67351
    34İzleyin

    Serendipity < 2.6.1 Authentication Bypass via Username Collision

    YüksekCVSS 8,7İstismar yokEPSS %1

    s9y · serendipity30 Tem 2026

  • CVE-2026-76207
    34İzleyin

    phpMyFAQ before 4.1.7 2FA Bypass via Remember-Me Cookie

    YüksekCVSS 8,6İstismar yokEPSS %0

    phpmyfaq · phpmyfaq19 Ağu 2026

  • CVE-2024-9216
    32İzleyin

    Authentication Bypass in gaizhenbiao/ChuanhuChatGPT

    YüksekCVSS 8,1İstismar yokEPSS %1

    gaizhenbiao · chuanhuchatgpt20 Mar 2025

  • CVE-2026-42452
    32İzleyin

    Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTP

    YüksekCVSS 8,1İstismar yokEPSS %0

    termix-ssh · termix8 May 2026

  • CVE-2024-11302
    32İzleyin

    Missing check_access in lollms_binding_infos in parisneo/lollms

    YüksekCVSS 8,0İstismar yokEPSS %0

    parisneo · parisneo/lollms20 Mar 2025

  • CVE-2026-93994
    32İzleyin

    Apache MINA SSHD: Repeated-publickey policy bypass on server

    YüksekCVSS 8,1İstismar yok

    apache software foundation · apache mina sshdBugün

  • CVE-2024-12136
    31İzleyin

    Improper Access Control in Elfatek Elektronics' ANKA JPD-00028

    YüksekCVSS 7,8İstismar yokEPSS %0

    elfatek · anka jpd00028 firmware19 Mar 2025

  • CVE-2026-55957
    30İzleyin

    Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind

    YüksekCVSS 7,3Kavram kanıtıEPSS %3

    apache · tomcat29 Haz 2026

  • CVE-2022-2821
    30İzleyin

    Missing Critical Step in Authentication in namelessmc/nameless

    YüksekCVSS 7,5İstismar yokEPSS %1

    namelessmc · nameless15 Ağu 2022

  • CVE-2024-20153
    30İzleyin

    In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID.

    YüksekCVSS 7,5İstismar yokEPSS %0

    linuxfoundation · yocto6 Oca 2025

  • CVE-2023-52424
    29İzleyin

    The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WE

    YüksekCVSS 7,4İstismar yokEPSS %1

    17 May 2024

  • CVE-2026-40542
    29İzleyin

    Apache HttpClient: SCRAM-SHA-256 mutual authentication bypass may cause the client to accept authentication without proper mutual authentication verification

    YüksekCVSS 7,3İstismar yokEPSS %1

    apache · httpclient22 Nis 2026

Tüm zafiyet sınıfları