CWE-1390
73 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-1390page 2 of 2
- CVE-2025-32885MEDIUMCVSS 6.5EG 6.52025-05-01
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom message (into existing v1 networks) with any GID and Callsign via a software defined radio. This can be …
- CVE-2025-39596CRITICALCVSS 9.8EG 9.82025-04-17
Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects Quentn WP: from n/a through <= 1.2.8.
- CVE-2025-40552CRITICALCVSS 9.8EG 9.82026-01-28
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
- CVE-2025-40554CRITICALCVSS 9.8EG 9.82026-01-28
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
- CVE-2025-47479MEDIUMCVSS 5.3EG 5.32025-07-04
Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This issue affects WP Compress: from n/a through <= 6.30.30.
- CVE-2025-47889CRITICALCVSS 9.8EG 9.82025-05-14
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any usernam…
- CVE-2025-47995MEDIUMCVSS 6.5EG 6.52025-07-18
Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
- CVE-2025-49201HIGHCVSS 8.1EG 8.12025-10-14
A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.…
- CVE-2025-50173HIGHCVSS 7.8EG 7.82025-08-12
Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2025-5484HIGHCVSS 8.3EG 8.32025-06-12
A username and password are required to authenticate to the central SinoTrack device management interface. The username for all devices is an identifier printed on the receiver. The default password is well-known and common to all devic…
- CVE-2025-57713HIGHCVSS 7.5EG 7.52026-02-11
A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: File …
- CVE-2025-59249HIGHCVSS 8.8EG 8.82025-10-14
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- CVE-2025-63807CRITICALCVSS 9.8EG 7.52025-11-20
An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perf…
- CVE-2025-70994HIGHCVSS 7.3EG 7.32026-04-23
Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implementing rolling codes or cryptographic ch…
- CVE-2025-7326HIGHCVSS 7.0EG 7.02025-07-08
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no futur…
- CVE-2026-0204HIGHCVSS 8.0EG 8.02026-04-29
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
- CVE-2026-40417HIGHCVSS 7.8EG 7.82026-05-12
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
- CVE-2026-44237HIGHCVSS 8.1EG 8.12026-05-29
FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_id is required. The validateClient() met…
- CVE-2026-4828HIGHCVSS 8.2EG 8.22026-04-01
Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multi-factor authentication via a crafted login request.
- CVE-2026-4924HIGHCVSS 8.2EG 8.22026-04-01
Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials to bypass multifactor authentication and gain unauthorized access to the…
- CVE-2026-49322MEDIUMCVSS 4.3EG 4.32026-05-29
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network to recover the user-set unlock PIN by pass…
- CVE-2026-49323MEDIUMCVSS 4.3EG 4.32026-05-29
Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the in-vehicle network t…
- CVE-2026-6886CRITICALCVSS 9.8EG 9.82026-04-23
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, allowing unauthenticated remote attackers to log into the system as any user.
Map vulnerabilities like CWE-1390 to your infrastructure
EchelonGraph correlates every CVE — across CWE-1390 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →