The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
81 vulnerabilities with CWE-1390
CVE-2025-11084
HIGH
DataMosaix Private Cloud - Auth Bypass
CVE-2025-59249
HIGH
Microsoft Exchange Server - Privilege Escalation
CVSS 8.8
CVE-2025-49201
HIGH
Fortinet FortiPAM 1.0.0-1.4.2 and FortiSwitchManager 7.2.0-7.2.4 - Weak Authentication
CVSS 8.1
CVE-2025-30468
MEDIUM
iPadOS < 26.0 - Unauthenticated Private Browsing Tab Access
CVSS 6.5
CVE-2025-50173
HIGH
Windows Installer - Privilege Escalation
CVSS 7.8
CVE-2025-47995
MEDIUM
Azure Machine Learning - Privilege Escalation
CVSS 6.5
CVE-2025-1727
HIGH
End-of-Train/Head-of-Train Protocol - Unauthenticated Brake Command Injection via RF Spoofing
CVSS 8.1
CVE-2025-7326
HIGH
ASP.NET Core - Privilege Escalation
CVSS 7.0
CVE-2025-47479
MEDIUM
AresIT WP Compress <6.30.30 - Auth Bypass
CVSS 5.3
CVE-2025-5484
HIGH
SinoTrack IOT PC Platform - Weak Authentication via Default Credentials
CVSS 8.3
CVE-2025-0605
MEDIUM
GitLab CE/EE <17.10.7-18.0.1 - Auth Bypass
CVSS 4.6
CVE-2025-32885
MEDIUM
goTenna v1 <5.5.3-0.25.5 - Code Injection
CVSS 6.5
CVE-2025-39596
CRITICAL
Quentn WP <1.2.8 - Privilege Escalation
CVSS 9.8
CVE-2025-27740
HIGH
Windows Active Directory Certificate Services - Privilege Escalation
CVSS 8.8
CVE-2025-26635
MEDIUM
Windows 10/11, Server 2019/2022 - Weak Authentication in Windows Hello
CVSS 6.5
CVE-2025-29991
LOW
Yubico YubiKey 5.4.1-5.7.3 - Info Disclosure
CVSS 2.2
CVE-2025-31676
HIGH
Drupal Email TFA <2.0.3 - Auth Bypass
CVSS 8.8
CVE-2025-29994
HIGH
CAP back office application < 2.0.4 - Unauthenticated Weak Authentication via API Endpoint
CVE-2025-24070
HIGH
ASP.NET Core & Visual Studio - Privilege Escalation
CVSS 7.0
CVE-2025-1293
HIGH
Hermes < 0.5.0 - Authentication Bypass via Improper AWS ALB JWT Validation
CVSS 8.2
CVE-2025-1387
CRITICAL
Orca HCM < 11.0 - Unauthenticated Weak Authentication
CVSS 9.8
CVE-2025-26343
HIGH
Q-Free MaxTime <= 2.11.0 - Auth Bypass
CVSS 8.1
CVE-2025-23058
HIGH
ClearPass Policy Manager - Privilege Escalation
CVSS 8.8
CVE-2025-21552
MEDIUM
Oracle JD Edwards <9.2.9.2 - Unauthorized Access
CVSS 6.5
CVE-2024-32119
MEDIUM
Fortinet FortiClientEMS <7.2.4 - Auth Bypass
CVSS 4.8
Details
Vulnerabilities
81