İçeriğe atla
Noroxi

CWE-308 · 16 kayıt

Use of Single-factor Authentication

Bu sınıftaki CVE’ler

16 kayıt

  • CVE-2026-58240
    39İzleyin

    Missing Authentication check in SAP NetWeaver (Message Server)

    KritikCVSS 9,8İstismar yokEPSS %1

    sap_se · sap netweaver (message server)7 Eyl 2026

  • CVE-2026-15616
    36İzleyin

    Local MFA not enforced during SSO sign-in

    KritikCVSS 9,1İstismar yokEPSS %1

    logto · logto23 Tem 2026

  • CVE-2026-67611
    34İzleyin

    OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration

    YüksekCVSS 8,6İstismar yokEPSS %1

    open-emr · openemr3 Ağu 2026

  • CVE-2025-42959
    32İzleyin

    Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476

    YüksekCVSS 8,1İstismar yokEPSS %1

    sap_se · sap netweaver abap server and abap platform7 Tem 2025

  • CVE-2026-45749
    32İzleyin

    Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password

    YüksekCVSS 8,1İstismar yokEPSS %0

    termix · termix5 Haz 2026

  • CVE-2024-47652
    30İzleyin

    Insecure Authentication Vulnerability

    YüksekCVSS 7,6İstismar yokEPSS %0

    shilpisoft · client dashboard4 Eki 2024

  • CVE-2023-49075
    28İzleyin

    Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewalls

    YüksekCVSS 7,2İstismar yokEPSS %1

    pimcore · admin classic bundle28 Kas 2023

  • CVE-2026-85590
    28İzleyin

    phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable

    YüksekCVSS 7,1İstismar yokEPSS %1

    thorsten · phpmyfaq4 Eyl 2026

  • CVE-2026-56022
    27İzleyin

    Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of ad

    OrtaCVSS 6,9İstismar yokEPSS %1

    webmin · webmin18 Haz 2026

  • CVE-2023-25681
    26İzleyin

    IBM Spectrum Virtualize security bypass

    OrtaCVSS 6,5İstismar yokEPSS %1

    ibm · spectrum virtualize5 Mar 2024

  • CVE-2023-34228
    26İzleyin

    In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions

    OrtaCVSS 6,5İstismar yokEPSS %0

    jetbrains · teamcity31 May 2023

  • CVE-2024-27928
    23İzleyin

    Vantage6: 2FA can be circumvented with hacked email access

    OrtaCVSS 5,9İstismar yokEPSS %0

    vantage6 · vantage617 Haz 2026

  • CVE-2023-50934
    21İzleyin

    IBM PowerSC improper authentication

    OrtaCVSS 5,3İstismar yokEPSS %0

    ibm · powersc1 Şub 2024

  • CVE-2026-79763
    21İzleyin

    Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)

    OrtaCVSS 5,3İstismar yokEPSS %0

    termix-ssh · termix6 gün önce

  • CVE-2024-50618
    17İzleyin

    A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to byp

    OrtaCVSS 4,3İstismar yokEPSS %0

    cipplanner · cipace11 Şub 2026

  • CVE-2026-33550
    10İzleyin

    SOGo before 5.12.5 does not renew the OTP if a user disables/enables it, and has a too short length (only 12 digits instead of the 20 recomm

    DüşükCVSS 2,6İstismar yokEPSS %0

    alinto · sogo21 Mar 2026

Tüm zafiyet sınıfları