Skip to main content

CWE archive

CWE-294 CVEs

Programmatic archive

239 CVEs tagged with CWE-29435 Critical, 110 High, 83 Medium, 11 Low, 0 Unrated.

CVE-2023-47435

Published Apr 19, 2024

An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected pages.

CVSS 9.8 · Critical

CVE-2024-29901

Published Mar 29, 2024

The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with Next.js. A user can reuse an expired session by controlling…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49231

Published Mar 29, 2024

An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.

CVSS 9.8 · Critical

CVE-2023-46892

Published Jan 23, 2024

The radio frequency communication protocol being used by Meross MSH30Q 4.5.23 is vulnerable to replay attacks, allowing attackers to record and replay previously captured communic…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50128

Published Jan 11, 2024

The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for each request, which results in an attacker being able to co…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45794

Published Nov 14, 2023

A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.4.0), Mendix Applications using Mendix 7 (All versions < V7.23.37), Mendix Applicati…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41890

Published Sep 19, 2023

Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provider. Prior to versions 1.0.3 and 2.9.2, when a response is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30909

Published Sep 14, 2023

A remote authentication bypass issue exists in some OneView APIs.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-48507

Published Jul 6, 2023

Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-29158

Published Jun 19, 2023

SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-of-service condition or a loss of data integrity.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 239 CVEsPage 5 of 10