The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.
96 vulnerabilities with CWE-303
CVE-2024-8642
HIGH
Eclipse Dataspace Components <0.9.0 - Auth Bypass
CVSS 8.1
CVE-2024-25157
MEDIUM
GoAnywhere MFT <7.6.0 - Auth Bypass
CVSS 6.5
CVE-2024-7593
CRITICAL
KEV
Ivanti Virtual Traffic Manager Authentication Bypass (CVE-2024-7593)
CVSS 9.8
CVE-2024-41829
LOW
JetBrains TeamCity < 2024.07 - OAuth Code Theft via Space Application Connection
CVSS 3.5
CVE-2024-34722
HIGH
Android - Authentication Bypass in BLE Legacy Pairing Protocol
CVSS 8.8
CVE-2024-5658
MEDIUM
born05/two-factor_authentication < 3.3.4 - Improper Authentication via TOTP Token Reuse
CVSS 4.8
CVE-2024-4332
CRITICAL
Tripwire Enterprise 9.1.0 - Auth Bypass
CVE-2024-4985
CRITICAL
GitHub Enterprise Server - Auth Bypass
CVSS 9.8
CVE-2024-35190
MEDIUM
Asterisk <18.23.0 - Info Disclosure
CVSS 5.8
CVE-2024-32879
MEDIUM
Python Social Auth <5.4.1 - Info Disclosure
CVSS 4.9
CVE-2024-26248
HIGH
Windows Kerberos - Privilege Escalation
CVSS 7.5
CVE-2024-3046
HIGH
Eclipse Kura 5.0.0-5.4.1 - Unauthenticated Log Retrieval and Privilege Escalation via LogServlet
CVSS 7.5
CVE-2023-4860
CRITICAL
Google Chrome <115.0.5790.98 - Sandbox Escape
CVSS 9.6
CVE-2023-44420
HIGH
D-Link DIR-X3260 Firmware < 1.04b01 - Unauthenticated Authentication Bypass via prog.cgi
CVSS 8.8
CVE-2023-34282
HIGH
D-Link DIR-2150 Firmware < 1.06 - Unauthenticated Authentication Bypass via SOAP API
CVSS 8.8
CVE-2023-34274
HIGH
D-Link DIR-2150 Firmware < 1.06 - Unauthenticated Authentication Bypass via SOAP API
CVSS 8.8
CVE-2023-32152
MEDIUM
D-Link DIR-2640 Firmware - Unauthenticated Authentication Bypass via HNAP LoginPassword
CVSS 6.5
CVE-2023-32148
MEDIUM
D-Link DIR-2640 Firmware - Unauthenticated Authentication Bypass via Crafted XML Login Request
CVSS 6.5
CVE-2023-31211
HIGH
Checkmk <2.2.0p18-2.0.0p39 - Auth Bypass
CVSS 8.8
CVE-2023-4641
MEDIUM
shadow-utils < 4.14.0 - Password Exposure via Uncleared Memory Buffer
CVSS 4.7
CVE-2023-5627
HIGH
NPort 6000 Series - Privilege Escalation
CVSS 7.5
CVE-2023-39953
MEDIUM
user_oidc <1.3.3 - Man-in-the-Middle
CVSS 4.8
CVE-2023-3326
CRITICAL
FreeBSD pam_krb5 - Improper Authentication via Unvalidated KDC Response
CVSS 9.8
CVE-2023-29357
CRITICAL
KEV
Sharepoint Dynamic Proxy Generator Unauth RCE
CVSS 9.8
CVE-2023-29129
CRITICAL
Mendix SAML Authentication Bypass via SAML Assertion
CVSS 9.1
Details
Vulnerabilities
96