CWE-305 · 156 kayıt
Authentication Bypass by Primary Weakness
Bu sınıftaki CVE’ler
156 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2025-31161Silahlaştırılmış | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instacrushftp · crushftp · CWE-305 | Kritik9,8 | KEV | %100,0 | 3 Nis 2025 |
66Bu hafta | CVE-2026-81578Silahlaştırılmış | PaperCut MF/NG: Authentication Bypasspapercut · papercut mf · CWE-305 | Yüksek8,8 | KEV | %4,5 | 28 Ağu 2026 |
60Bu hafta | CVE-2020-10923Silahlaştırılmış | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 rnetgear · r6700 firmware · CWE-305 | Yüksek8,8 | — | %84,7 | 28 Tem 2020 |
54Planlayın | CVE-2023-34124Silahlaştırılmış | The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass.sonicwall · analytics · CWE-305 | Kritik9,8 | — | %50,5 | 12 Tem 2023 |
45Planlayın | CVE-2025-32011İstismar yok | KUNBUS Revolution Pi Authentication Bypass by Primary Weaknesskunbus gmbh · revolution pi pictory · CWE-305 | Kritik9,3 | — | %27,5 | 1 May 2025 |
44Planlayın | CVE-2022-2651Kavram kanıtı | Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrmjoinbookwyrm · bookwyrm · CWE-305 | Kritik9,8 | — | %15,8 | 4 Ağu 2022 |
44Planlayın | CVE-2023-0777Kavram kanıtı | Authentication Bypass by Primary Weakness in modoboa/modoboamodoboa · modoboa · CWE-305 | Kritik9,8 | — | %15,2 | 10 Şub 2023 |
43Planlayın | CVE-2023-28126İstismar yok | An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploitinivanti · avalanche · CWE-305 | Orta5,9 | — | %66,7 | 9 May 2023 |
42Planlayın | CVE-2021-26102Kavram kanıtı | A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated fortinet · fortiwan · CWE-305 | Kritik9,1 | — | %19,7 | 19 Ara 2024 |
42Planlayın | CVE-2025-13915İstismar yok | Authentication bypass in IBM API Connectibm · api connect · CWE-305 | Kritik9,8 | — | %9,0 | 26 Ara 2025 |
40Planlayın | CVE-2024-20674Kavram kanıtı | Windows Kerberos Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-305 | Yüksek8,8 | — | %17,2 | 9 Oca 2024 |
40Planlayın | CVE-2022-0547İstismar yok | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes uopenvpn · openvpn · CWE-305 | Kritik9,8 | — | %3,6 | 18 Mar 2022 |
40Planlayın | CVE-2024-1403Kavram kanıtı | Authentication Bypass in OpenEdge Authentication Gateway and AdminServerprogress · openedge · CWE-305 | Kritik9,8 | — | %3,3 | 27 Şub 2024 |
40Planlayın | CVE-2025-4320İstismar yok | Information Disclosure in Birebirsoft's Sufirmambirebirsoft software and technology solutions · sufirmam · CWE-305 | Kritik10,0 | — | %0,5 | 23 Oca 2026 |
39İzleyin | CVE-2020-24683İstismar yok | Authentication Bypass in Symphony Plusabb · symphony \+ historian · CWE-305 | Kritik9,8 | — | %1,5 | 22 Ara 2020 |
39İzleyin | CVE-2020-15787İstismar yok | A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16).siemens · simatic hmi united comfort panels firmware · CWE-305 | Kritik9,8 | — | %1,5 | 9 Eyl 2020 |
39İzleyin | CVE-2021-21403İstismar yok | Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/serverkongchuanhujiao project · kongchuanhujiao · CWE-305 | Kritik9,8 | — | %1,4 | 26 Mar 2021 |
39İzleyin | CVE-2024-50478Kavram kanıtı | WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerabilityswoopnow · 1-click login\ · CWE-305 | Kritik9,8 | — | %1,1 | 28 Eki 2024 |
39İzleyin | CVE-2023-1307İstismar yok | Authentication Bypass by Primary Weakness in froxlor/froxlorfroxlor · froxlor · CWE-305 | Kritik9,8 | — | %1,1 | 9 Mar 2023 |
39İzleyin | CVE-2023-34137İstismar yok | SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authenticatiosonicwall · analytics · CWE-305 | Kritik9,8 | — | %1,0 | 12 Tem 2023 |
39İzleyin | CVE-2024-1202İstismar yok | Authentication Bypass in XPodas' Octopodxpodas · octopod · CWE-305 | Kritik9,8 | — | %0,9 | 20 Mar 2024 |
39İzleyin | CVE-2026-19349İstismar yok | Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2CWE-305 | Kritik9,8 | — | %0,8 | 16 Ağu 2026 |
39İzleyin | CVE-2023-1833İstismar yok | Authentication Bypass in Redline Routerredline · router firmware · CWE-305 | Kritik9,8 | — | %0,8 | 14 Nis 2023 |
39İzleyin | CVE-2021-28503İstismar yok | In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote atarista · eos · CWE-305 | Kritik9,8 | — | %0,7 | 4 Şub 2022 |
39İzleyin | CVE-2023-6153İstismar yok | Authentication Bypass in TeoSOFT Software TeoBASEteosoft software · teobase · CWE-305 | Kritik9,8 | — | %0,7 | 27 Mar 2024 |
- CVE-2025-3116199Hemen
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy insta
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100crushftp · crushftp3 Nis 2025
- CVE-2026-8157866Bu hafta
PaperCut MF/NG: Authentication Bypass
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %4papercut · papercut mf28 Ağu 2026
- CVE-2020-1092360Bu hafta
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 r
YüksekCVSS 8,8SilahlaştırılmışEPSS %85netgear · r6700 firmware28 Tem 2020
- CVE-2023-3412454Planlayın
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass.
KritikCVSS 9,8SilahlaştırılmışEPSS %50sonicwall · analytics12 Tem 2023
- CVE-2025-3201145Planlayın
KUNBUS Revolution Pi Authentication Bypass by Primary Weakness
KritikCVSS 9,3İstismar yokEPSS %27kunbus gmbh · revolution pi pictory1 May 2025
- CVE-2022-265144Planlayın
Authentication Bypass by Primary Weakness in bookwyrm-social/bookwyrm
KritikCVSS 9,8Kavram kanıtıEPSS %16joinbookwyrm · bookwyrm4 Ağu 2022
- CVE-2023-077744Planlayın
Authentication Bypass by Primary Weakness in modoboa/modoboa
KritikCVSS 9,8Kavram kanıtıEPSS %15modoboa · modoboa10 Şub 2023
- CVE-2023-2812643Planlayın
An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploitin
OrtaCVSS 5,9İstismar yokEPSS %67ivanti · avalanche9 May 2023
- CVE-2021-2610242Planlayın
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated
KritikCVSS 9,1Kavram kanıtıEPSS %20fortinet · fortiwan19 Ara 2024
- CVE-2025-1391542Planlayın
Authentication bypass in IBM API Connect
KritikCVSS 9,8İstismar yokEPSS %9ibm · api connect26 Ara 2025
- CVE-2024-2067440Planlayın
Windows Kerberos Security Feature Bypass Vulnerability
YüksekCVSS 8,8Kavram kanıtıEPSS %17microsoft · windows 10 15079 Oca 2024
- CVE-2022-054740Planlayın
OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes u
KritikCVSS 9,8İstismar yokEPSS %4openvpn · openvpn18 Mar 2022
- CVE-2024-140340Planlayın
Authentication Bypass in OpenEdge Authentication Gateway and AdminServer
KritikCVSS 9,8Kavram kanıtıEPSS %3progress · openedge27 Şub 2024
- CVE-2025-432040Planlayın
Information Disclosure in Birebirsoft's Sufirmam
KritikCVSS 10,0İstismar yokEPSS %1birebirsoft software and technology solutions · sufirmam23 Oca 2026
- CVE-2020-2468339İzleyin
Authentication Bypass in Symphony Plus
KritikCVSS 9,8İstismar yokEPSS %1abb · symphony \+ historian22 Ara 2020
- CVE-2020-1578739İzleyin
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16).
KritikCVSS 9,8İstismar yokEPSS %1siemens · simatic hmi united comfort panels firmware9 Eyl 2020
- CVE-2021-2140339İzleyin
Authentication Bypass by Primary Weakness in github.com/kongchuanhujiao/server
KritikCVSS 9,8İstismar yokEPSS %1kongchuanhujiao project · kongchuanhujiao26 Mar 2021
- CVE-2024-5047839İzleyin
WordPress 1-Click Login: Passwordless Authentication plugin 1.4.5 - Broken Authentication vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %1swoopnow · 1-click login\28 Eki 2024
- CVE-2023-130739İzleyin
Authentication Bypass by Primary Weakness in froxlor/froxlor
KritikCVSS 9,8İstismar yokEPSS %1froxlor · froxlor9 Mar 2023
- CVE-2023-3413739İzleyin
SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authenticatio
KritikCVSS 9,8İstismar yokEPSS %1sonicwall · analytics12 Tem 2023
- CVE-2024-120239İzleyin
Authentication Bypass in XPodas' Octopod
KritikCVSS 9,8İstismar yokEPSS %1xpodas · octopod20 Mar 2024
- CVE-2026-1934939İzleyin
Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via an OAuth2
KritikCVSS 9,8İstismar yokEPSS %116 Ağu 2026
- CVE-2023-183339İzleyin
Authentication Bypass in Redline Router
KritikCVSS 9,8İstismar yokEPSS %1redline · router firmware14 Nis 2023
- CVE-2021-2850339İzleyin
In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote at
KritikCVSS 9,8İstismar yokEPSS %1arista · eos4 Şub 2022
- CVE-2023-615339İzleyin
Authentication Bypass in TeoSOFT Software TeoBASE
KritikCVSS 9,8İstismar yokEPSS %1teosoft software · teobase27 Mar 2024