Vulnerabilities > Authentication Bypass by Primary Weakness

DATE CVE VULNERABILITY TITLE RISK
2024-11-15 CVE-2023-20154 A vulnerability in the external authentication mechanism of Cisco Modeling Labs could allow an unauthenticated, remote attacker to access the web interface with administrative privileges. This vulnerability is due to the improper handling of certain messages that are returned by the associated external authentication server.
network
low complexity
CWE-305
critical
9.1
2024-10-17 CVE-2024-9683 A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided.
network
high complexity
CWE-305
4.8
2024-03-05 CVE-2023-7103 Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authentication Bypass.This issue affects UFace 5: through 12022024.
network
low complexity
CWE-305
critical
9.8
2023-09-11 CVE-2023-36497 Authentication Bypass by Primary Weakness vulnerability in Doverfuelingsolutions Maglink LX web Console Configuration
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 could allow a guest user to elevate to admin privileges.
network
low complexity
doverfuelingsolutions CWE-305
8.8
2023-07-17 CVE-2023-2959 Authentication Bypass by Primary Weakness vulnerability in Olivaekspertiz Oliva Ekspertiz
Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users.This issue affects Oliva Expertise EKS: before 1.2.
network
low complexity
olivaekspertiz CWE-305
7.5
2023-04-14 CVE-2023-1833 Authentication Bypass by Primary Weakness vulnerability in Redline Router Firmware
Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass.This issue affects Redline Router: before 7.17.
network
low complexity
redline CWE-305
critical
9.8
2023-03-10 CVE-2023-1307 Authentication Bypass by Primary Weakness vulnerability in Froxlor
Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.
network
low complexity
froxlor CWE-305
critical
9.8
2023-01-18 CVE-2022-3100 Authentication Bypass by Primary Weakness vulnerability in multiple products
A flaw was found in the openstack-barbican component.
network
high complexity
openstack redhat CWE-305
5.9
2022-08-04 CVE-2022-2651 Authentication Bypass by Primary Weakness vulnerability in Joinbookwyrm Bookwyrm
Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.
network
low complexity
joinbookwyrm CWE-305
critical
9.8
2022-03-30 CVE-2021-45031 Authentication Bypass by Primary Weakness vulnerability in Mepsan Stawiz Usc++
A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets attackers to generate high privileged accounts passwords.
network
high complexity
mepsan CWE-305
7.7