Vulnerabilities (CVE)

Filtered by CWE-1390
Total 95 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-47479 1 Wpcompress 1 Wp Compress 2026-06-17 N/A 5.3 MEDIUM
Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This issue affects WP Compress: from n/a through <= 6.30.30.
CVE-2025-40554 1 Solarwinds 1 Web Help Desk 2026-06-17 N/A 9.8 CRITICAL
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
CVE-2025-40552 1 Solarwinds 1 Web Help Desk 2026-06-17 N/A 9.8 CRITICAL
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
CVE-2025-39596 2026-06-17 N/A 9.8 CRITICAL
Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects Quentn WP: from n/a through <= 1.2.8.
CVE-2025-32885 1 Gotenna 3 Gotenna, Mesh, Mesh Firmware 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom message (into existing v1 networks) with any GID and Callsign via a software defined radio. This can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised.
CVE-2025-31676 1 Email Tfa Project 1 Email Tfa 2026-06-17 N/A 8.8 HIGH
Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3.
CVE-2025-30468 1 Apple 2 Ipados, Iphone Os 2026-06-17 N/A 6.5 MEDIUM
This issue was addressed through improved state management. This issue is fixed in iOS 26 and iPadOS 26. Private Browsing tabs may be accessed without authentication.
CVE-2025-30412 3 Acronis, Linux, Microsoft 3 Cyber Protect, Linux Kernel, Windows 2026-06-17 N/A 10.0 CRITICAL
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
CVE-2025-30411 3 Acronis, Linux, Microsoft 3 Cyber Protect, Linux Kernel, Windows 2026-06-17 N/A 10.0 CRITICAL
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
CVE-2025-29994 2026-06-17 N/A N/A
This vulnerability exists in the CAP back office application due to improper authentication check at the API endpoint. An unauthenticated remote attacker with a valid login ID could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to other user accounts.
CVE-2025-29991 2026-06-17 N/A 2.2 LOW
Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial signature verification.
CVE-2025-27740 1 Microsoft 7 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 4 more 2026-06-17 N/A 8.8 HIGH
Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.
CVE-2025-26635 1 Microsoft 8 Windows 10 1809, Windows 10 21h2, Windows 10 22h2 and 5 more 2026-06-17 N/A 6.5 MEDIUM
Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network.
CVE-2025-26343 1 Q-free 1 Maxtime 2026-06-17 N/A 8.1 HIGH
A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to brute-force user PINs via multiple crafted HTTP requests.
CVE-2025-24070 1 Microsoft 2 Asp.net Core, Visual Studio 2022 2026-06-17 N/A 7.0 HIGH
Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-23058 1 Arubanetworks 1 Clearpass Policy Manager 2026-06-17 N/A 8.8 HIGH
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.
CVE-2025-21552 1 Oracle 1 Jd Edwards Enterpriseone Orchestrator 2026-06-17 N/A 6.5 MEDIUM
Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
CVE-2025-1727 2026-06-17 N/A 8.1 HIGH
The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH checksum for packet creation. It is possible to create these EoT and HoT packets with a software defined radio and issue brake control commands to the EoT device, disrupting operations or potentially overwhelming the brake systems.
CVE-2025-1387 1 Learningdigital 1 Orca Hcm 2026-06-17 N/A 9.8 CRITICAL
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.
CVE-2025-1293 1 Hashicorp 1 Hermes 2026-06-17 N/A 8.2 HIGH
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.