The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
154 vulnerabilities with CWE-305
CVE-2024-10394
HIGH
OpenAFS < 1.6.25 - Authentication Bypass via PAG Throttling Mechanism
CVSS 7.8
CVE-2024-10082
HIGH
CodeChecker <6.24.1 - Privilege Escalation
CVSS 8.7
CVE-2024-50478
CRITICAL
Swoop 1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass
CVSS 9.8
CVE-2024-9683
MEDIUM
Quay - Authentication Bypass via Truncated Password
CVSS 4.8
CVE-2024-20463
MEDIUM
Cisco ATA 190 Series - Unauthenticated RCE
CVSS 5.4
CVE-2024-8642
HIGH
Eclipse Dataspace Components <0.9.0 - Auth Bypass
CVSS 8.1
CVE-2024-5957
MEDIUM
Trellix Intrusion Prevention System Manager < 11.1.7.97 - Unauthenticated Authentication Bypass
CVSS 6.3
CVE-2024-5956
MEDIUM
Trellix Intrusion Prevention System Manager - Unauthenticated Authentication Bypass
CVSS 6.5
CVE-2024-7557
HIGH
Red Hat OpenShift AI - Authentication Bypass and Privilege Escalation via ServiceAccount Token Exposure
CVSS 8.8
CVE-2024-4784
MEDIUM
GitLab EE <17.0.6-17.2.2 - Auth Bypass
CVSS 4.2
CVE-2024-6637
HIGH
WooCommerce - Social Login <2.7.3 - Privilege Escalation
CVSS 7.3
CVE-2024-38433
MEDIUM
Nuvoton NPCM7xx Firmware < 10.10.19 - Authentication Bypass and Arbitrary Code Execution via U-Boot Image Header
CVSS 6.7
CVE-2024-39899
MEDIUM
PrivateBin 1.5.0-1.7.3 - Authentication Bypass via YOURLS Proxy URL Validation
CVSS 5.3
CVE-2024-37085
MEDIUM
KEV
VMware ESXi - Authentication Bypass via Recreated Active Directory Group
CVSS 6.8
CVE-2024-36388
CRITICAL
MileSight DeviceHub - Info Disclosure
CVSS 10.0
CVE-2024-34077
HIGH
MantisBT < 2.26.2 - Unauthenticated Account Takeover via Password Reset Token Reuse
CVSS 7.3
CVE-2024-20378
HIGH
Cisco IP Phone 6821/6841/6851/6861/6871/7811 < 12.0.4 - Unauthenticated Information Disclosure
CVSS 7.5
CVE-2024-3847
MEDIUM
Google Chrome <124.0.6367.60 - Auth Bypass
CVSS 6.1
CVE-2024-1202
CRITICAL
XPodas Octopod < v1 - Authentication Bypass
CVSS 9.8
CVE-2024-1403
CRITICAL
OpenEdge < 11.7.19 - Authentication Bypass via Credential Handling Failure
CVSS 10.0
CVE-2024-20015
HIGH
Android - Local Privilege Escalation via Telephony Permissions Bypass
CVSS 7.8
CVE-2024-20674
HIGH
Windows Kerberos - Privilege Escalation
CVSS 8.8
CVE-2023-46611
MEDIUM
YOP Poll < 6.5.28 - Authentication Bypass via Broken CAPTCHA Control
CVSS 5.3
CVE-2023-20154
CRITICAL
Cisco Modeling Labs 2.3-2.5.1 - Authentication Bypass via External Auth Server Message Handling
CVSS 9.1
CVE-2023-41920
CRITICAL
Kiloview P1/P2 - Authentication Bypass via Hardcoded IP
CVSS 9.8
Details
Vulnerabilities
154