Skip to main content

CWE archive

CWE-294 CVEs

Programmatic archive

250 CVEs tagged with CWE-29438 Critical, 116 High, 85 Medium, 11 Low, 0 Unrated.

CVE-2022-48507

Published Jul 6, 2023

Vulnerability of identity verification being bypassed in the storage module. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-29158

Published Jun 19, 2023

SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-of-service condition or a loss of data integrity.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47930

Published Apr 21, 2023

An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used through the MPC implementation, which makes replaying and spoof…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1886

Published Apr 5, 2023

Authentication Bypass by Capture-replay in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1537

Published Mar 21, 2023

Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-45789

Published Jan 31, 2023

A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbus functions on the controller when hijacking an authenticat…

CVSS 8.1 · High
evidence mentions
3
Buzz score
21.9

CVE-2023-0036

Published Jan 9, 2023

platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0035

Published Jan 9, 2023

softbus_client_stub in communication subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local atta…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2226

Published Dec 22, 2022

An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-25837

Published Dec 12, 2022

Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 250 CVEsPage 6 of 10