CWE-308 · 16 kayıt
Use of Single-factor Authentication
Bu sınıftaki CVE’ler
16 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-58240İstismar yok | Missing Authentication check in SAP NetWeaver (Message Server)sap_se · sap netweaver (message server) · CWE-308 | Kritik9,8 | — | %0,5 | 7 Eyl 2026 |
36İzleyin | CVE-2026-15616İstismar yok | Local MFA not enforced during SSO sign-inlogto · logto · CWE-308 | Kritik9,1 | — | %0,5 | 23 Tem 2026 |
34İzleyin | CVE-2026-67611İstismar yok | OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configurationopen-emr · openemr · CWE-308 | Yüksek8,6 | — | %0,8 | 3 Ağu 2026 |
32İzleyin | CVE-2025-42959İstismar yok | Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476sap_se · sap netweaver abap server and abap platform · CWE-308 | Yüksek8,1 | — | %0,5 | 7 Tem 2025 |
32İzleyin | CVE-2026-45749İstismar yok | Termix's TOTP two-factor authentication can be disabled or bypassed using only the account passwordtermix · termix · CWE-308 | Yüksek8,1 | — | %0,5 | 5 Haz 2026 |
30İzleyin | CVE-2024-47652İstismar yok | Insecure Authentication Vulnerabilityshilpisoft · client dashboard · CWE-308 | Yüksek7,6 | — | %0,4 | 4 Eki 2024 |
28İzleyin | CVE-2023-49075İstismar yok | Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewallspimcore · admin classic bundle · CWE-308 | Yüksek7,2 | — | %1,4 | 28 Kas 2023 |
28İzleyin | CVE-2026-85590İstismar yok | phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disablethorsten · phpmyfaq · CWE-308 | Yüksek7,1 | — | %0,5 | 4 Eyl 2026 |
27İzleyin | CVE-2026-56022İstismar yok | Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of adwebmin · webmin · CWE-308 | Orta6,9 | — | %0,6 | 18 Haz 2026 |
26İzleyin | CVE-2023-25681İstismar yok | IBM Spectrum Virtualize security bypassibm · spectrum virtualize · CWE-308 | Orta6,5 | — | %0,6 | 5 Mar 2024 |
26İzleyin | CVE-2023-34228İstismar yok | In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actionsjetbrains · teamcity · CWE-308 | Orta6,5 | — | %0,4 | 31 May 2023 |
23İzleyin | CVE-2024-27928İstismar yok | Vantage6: 2FA can be circumvented with hacked email accessvantage6 · vantage6 · CWE-308 | Orta5,9 | — | %0,3 | 17 Haz 2026 |
21İzleyin | CVE-2023-50934İstismar yok | IBM PowerSC improper authenticationibm · powersc · CWE-308 | Orta5,3 | — | %0,4 | 1 Şub 2024 |
21İzleyin | CVE-2026-79763İstismar yok | Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)termix-ssh · termix · CWE-308 | Orta5,3 | — | %0,3 | 6 gün önce |
17İzleyin | CVE-2024-50618İstismar yok | A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypcipplanner · cipace · CWE-308 | Orta4,3 | — | %0,3 | 11 Şub 2026 |
10İzleyin | CVE-2026-33550İstismar yok | SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recommalinto · sogo · CWE-308 | Düşük2,6 | — | %0,2 | 21 Mar 2026 |
- CVE-2026-5824039İzleyin
Missing Authentication check in SAP NetWeaver (Message Server)
KritikCVSS 9,8İstismar yokEPSS %1sap_se · sap netweaver (message server)7 Eyl 2026
- CVE-2026-1561636İzleyin
Local MFA not enforced during SSO sign-in
KritikCVSS 9,1İstismar yokEPSS %1logto · logto23 Tem 2026
- CVE-2026-6761134İzleyin
OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
YüksekCVSS 8,6İstismar yokEPSS %1open-emr · openemr3 Ağu 2026
- CVE-2025-4295932İzleyin
Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476
YüksekCVSS 8,1İstismar yokEPSS %1sap_se · sap netweaver abap server and abap platform7 Tem 2025
- CVE-2026-4574932İzleyin
Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password
YüksekCVSS 8,1İstismar yokEPSS %0termix · termix5 Haz 2026
- CVE-2024-4765230İzleyin
Insecure Authentication Vulnerability
YüksekCVSS 7,6İstismar yokEPSS %0shilpisoft · client dashboard4 Eki 2024
- CVE-2023-4907528İzleyin
Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewalls
YüksekCVSS 7,2İstismar yokEPSS %1pimcore · admin classic bundle28 Kas 2023
- CVE-2026-8559028İzleyin
phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable
YüksekCVSS 7,1İstismar yokEPSS %1thorsten · phpmyfaq4 Eyl 2026
- CVE-2026-5602227İzleyin
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of ad
OrtaCVSS 6,9İstismar yokEPSS %1webmin · webmin18 Haz 2026
- CVE-2023-2568126İzleyin
IBM Spectrum Virtualize security bypass
OrtaCVSS 6,5İstismar yokEPSS %1ibm · spectrum virtualize5 Mar 2024
- CVE-2023-3422826İzleyin
In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions
OrtaCVSS 6,5İstismar yokEPSS %0jetbrains · teamcity31 May 2023
- CVE-2024-2792823İzleyin
Vantage6: 2FA can be circumvented with hacked email access
OrtaCVSS 5,9İstismar yokEPSS %0vantage6 · vantage617 Haz 2026
- CVE-2023-5093421İzleyin
IBM PowerSC improper authentication
OrtaCVSS 5,3İstismar yokEPSS %0ibm · powersc1 Şub 2024
- CVE-2026-7976321İzleyin
Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)
OrtaCVSS 5,3İstismar yokEPSS %0termix-ssh · termix6 gün önce
- CVE-2024-5061817İzleyin
A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to byp
OrtaCVSS 4,3İstismar yokEPSS %0cipplanner · cipace11 Şub 2026
- CVE-2026-3355010İzleyin
SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recomm
DüşükCVSS 2,6İstismar yokEPSS %0alinto · sogo21 Mar 2026