CWE-1390
73 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1390page 1 of 2
- CVE-2022-43400CRITICALCVSS 9.8EG 9.82022-10-21
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of…
- CVE-2022-45860MEDIUMCVSS 5.3EG 5.32023-05-03
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated a…
- CVE-2023-24890MEDIUMCVSS 6.5EG 6.52023-03-14
Microsoft OneDrive for iOS Security Feature Bypass Vulnerability
- CVE-2023-39439HIGHCVSS 8.8EG 8.82023-08-08
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.
- CVE-2023-4094MEDIUMCVSS 6.5EG 6.52023-09-19
ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified t…
- CVE-2023-41862MEDIUMCVSS 5.3EG 5.32024-12-13
Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0.
- CVE-2023-41900LOWCVSS 3.5EG 3.52023-09-15
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginServi…
- CVE-2023-49340CRITICALCVSS 9.8EG 9.82024-03-09
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.
- CVE-2023-53894CRITICALCVSS 9.8EG 9.82025-12-16
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass au…
- CVE-2024-0822HIGHCVSS 7.5EG 9.12024-01-25
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.
- CVE-2024-13239CRITICALCVSS 9.8EG 9.82025-01-09
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.
- CVE-2024-29038MEDIUMCVSS 4.3EG 4.32024-06-28
tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.
- CVE-2024-29837HIGHCVSS 8.8EG 8.82024-04-15
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.
- CVE-2024-32119MEDIUMCVSS 4.8EG 4.82025-06-10
An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploadi…
- CVE-2024-34451CRITICALCVSS 9.1EG 9.12024-06-16
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reve…
- CVE-2024-35248HIGHCVSS 7.3EG 7.32024-06-11
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
- CVE-2024-36787HIGHCVSS 8.8EG 8.82024-06-07
An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.
- CVE-2024-38182CRITICALCVSS 9.0EG 9.02024-07-31
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
- CVE-2024-38239HIGHCVSS 7.2EG 7.22024-09-10
Windows Kerberos Elevation of Privilege Vulnerability
- CVE-2024-39848CRITICALCVSS 9.1EG 9.12024-06-29
Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the …
- CVE-2024-41722MEDIUMCVSS 6.5EG 6.52024-09-26
In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited …
- CVE-2024-45367CRITICALCVSS 9.1EG 9.12024-10-03
The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.
- CVE-2024-45551MEDIUMCVSS 6.2EG 6.22025-04-07
Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.
- CVE-2024-47127MEDIUMCVSS 6.5EG 3.12024-09-26
In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. This vulnerability can be exploited if the d…
- CVE-2024-47397HIGHCVSS 7.5EG 7.52024-12-18
Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypassed with an undocumented specific string.
- CVE-2024-48886CRITICALCVSS 9.0EG 9.02025-01-14
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0…
- CVE-2024-49019HIGHCVSS 7.8EG 7.82024-11-12
Active Directory Certificate Services Elevation of Privilege Vulnerability
- CVE-2024-50563HIGHCVSS 7.3EG 7.32025-01-16
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiM…
- CVE-2024-52541HIGHCVSS 8.2EG 8.22025-02-19
Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
- CVE-2024-54092CRITICALCVSS 9.8EG 9.82025-04-08
A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial Edge Device Kit - arm64 V1.19 (All versions), Industrial Edge Device Kit - …
- CVE-2024-5891MEDIUMCVSS 4.2EG 4.22024-06-12
A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was created. This issue is …
- CVE-2024-6580MEDIUMCVSS 6.5EG 6.52024-07-08
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component…
- CVE-2024-8322MEDIUMCVSS 4.3EG 4.32024-09-10
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
- CVE-2025-0605MEDIUMCVSS 4.6EG 4.62025-05-22
An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.
- CVE-2025-11084HIGHCVSS 7.6EG 0.02025-11-11
A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a valid login-token cookie without knowing the users password. This vulnerability occurs when MFA is enabled but not compl…
- CVE-2025-12870CRITICALCVSS 9.8EG 9.82025-11-12
The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.
- CVE-2025-12871CRITICALCVSS 9.8EG 9.82025-11-12
The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.
- CVE-2025-1293HIGHCVSS 8.2EG 8.22025-02-20
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.
- CVE-2025-1387CRITICALCVSS 9.8EG 9.82025-02-17
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.
- CVE-2025-1727HIGHCVSS 8.1EG 8.12025-07-10
The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH checksum for packet creation. It is possible to create these EoT and HoT packets with a software defined radio and is…
- CVE-2025-21552MEDIUMCVSS 6.5EG 6.52025-01-21
Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low priv…
- CVE-2025-23058HIGHCVSS 8.8EG 8.82025-02-04
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restri…
- CVE-2025-24070HIGHCVSS 7.0EG 7.02025-03-11
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- CVE-2025-26343HIGHCVSS 8.1EG 8.12025-02-12
A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.
- CVE-2025-26635MEDIUMCVSS 6.5EG 6.52025-04-08
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
- CVE-2025-27740HIGHCVSS 8.8EG 8.82025-04-08
Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.
- CVE-2025-29991LOWCVSS 2.2EG 2.22025-04-03
Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, result…
- CVE-2025-29994HIGHCVSS 8.2EG 0.02025-03-13
This vulnerability exists in the CAP back office application due to improper authentication check at the API endpoint. An unauthenticated remote attacker with a valid login ID could exploit this vulnerability by manipulating API input para…
- CVE-2025-30468MEDIUMCVSS 6.5EG 6.52025-09-15
This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessed without authentication.
- CVE-2025-31676HIGHCVSS 8.8EG 8.82025-03-31
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.
Map vulnerabilities like CWE-1390 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1390 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →