The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
86 vulnerabilities with CWE-1390
CVE-2025-1387
CRITICAL
Orca HCM < 11.0 - Unauthenticated Weak Authentication
CVSS 9.8
CVE-2025-26343
HIGH
Q-Free MaxTime <= 2.11.0 - Auth Bypass
CVSS 8.1
CVE-2025-23058
HIGH
ClearPass Policy Manager - Privilege Escalation
CVSS 8.8
CVE-2025-21552
MEDIUM
Oracle JD Edwards <9.2.9.2 - Unauthorized Access
CVSS 6.5
CVE-2024-32119
MEDIUM
Fortinet FortiClientEMS <7.2.4 - Auth Bypass
CVSS 4.8
CVE-2024-54092
CRITICAL
Industrial Edge Device Kit - arm64/x86-64 <1.20.2-1/<1.21.1-1 - Inf...
CVSS 9.8
CVE-2024-45551
MEDIUM
Qualcomm FastConnect and Flight/QAM Firmware - Weak Authentication via Gatekeeper PIN Verification
CVSS 6.2
CVE-2024-52541
HIGH
Dell Client Platform BIOS - Privilege Escalation
CVSS 8.2
CVE-2024-50563
HIGH
Fortinet FortiManager/FortiAnalyzer <7.6.1/7.4.3 - RCE
CVSS 7.3
CVE-2024-48886
CRITICAL
Fortinet FortiOS/FortiProxy/FortiManager/FortiAnalyzer Cloud Weak Authentication Brute-Force
CVSS 9.0
CVE-2024-13239
CRITICAL
Drupal Two-factor Authentication < 8.x-1.5 - Weak Authentication
CVSS 9.8
CVE-2024-47397
HIGH
FXC Inc. AE1021 and AE1021PE <= 2.0.10 - Weak Authentication Bypass via Undocumented String
CVSS 7.5
CVE-2024-49019
HIGH
Active Directory Certificate Services - Privilege Escalation
CVSS 7.8
CVE-2024-45367
CRITICAL
ONS-S8 - Spectra Aggregation Switch - Auth Bypass
CVSS 9.1
CVE-2024-47127
MEDIUM
goTenna Pro < 1.6.1 and < 2.0.3 - Unauthenticated Message Injection via Software Defined Radio
CVSS 6.5
CVE-2024-41722
MEDIUM
goTenna Pro ATAK Plugin - Code Injection
CVSS 6.5
CVE-2024-8322
MEDIUM
Ivanti EPM <2022 SU6-2024 September - Auth Bypass
CVSS 4.3
CVE-2024-38239
HIGH
Windows Kerberos - Privilege Escalation
CVSS 7.2
CVE-2024-38182
CRITICAL
Microsoft Dynamics 365 - Privilege Escalation
CVSS 9.0
CVE-2024-6580
MEDIUM
IPWorks SSH <24.0.8945 - Path Traversal
CVSS 6.5
CVE-2024-39848
CRITICAL
Internet2 Grouper <5.6 - Auth Bypass
CVSS 9.1
CVE-2024-29038
MEDIUM
tpm2-tools 4.1-5.5.1 - Weak Authentication via Arbitrary Quote Data
CVSS 4.3
CVE-2024-34451
CRITICAL
Ghost < 5.85.1 - Authentication Rate-Limit Bypass via X-Forwarded-For Header Manipulation
CVSS 9.1
CVE-2024-5891
MEDIUM
Quay - Weak Authentication via OAuth Token
CVSS 4.2
CVE-2024-35248
HIGH
Microsoft Dynamics 365 Business Central - Elevation of Privilege via Weak Authentication
CVSS 7.3
Details
Vulnerabilities
86