Vulnerabilities (CVE)

Filtered by CWE-1390
Total 95 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-36787 1 Netgear 2 Wnr614, Wnr614 Firmware 2026-06-17 N/A 8.8 HIGH
An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.
CVE-2024-34451 1 Ghost 1 Ghost 2026-06-17 N/A 9.1 CRITICAL
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.
CVE-2024-32119 1 Fortinet 1 Forticlientems 2026-06-17 N/A 4.8 MEDIUM
An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.
CVE-2024-29837 1 Cs-technologies 1 Evolution 2026-06-17 N/A 8.8 HIGH
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any other user is already signed in.
CVE-2024-29038 1 Tpm2-tools Project 1 Tpm2-tools 2026-06-17 N/A 4.3 MEDIUM
tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.
CVE-2024-13239 1 Two-factor Authentication Project 1 Two-factor Authentication 2026-06-17 N/A 9.8 CRITICAL
Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.
CVE-2024-0822 1 Ovirt 1 Ovirt-engine 2026-06-17 N/A 7.5 HIGH
An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.
CVE-2023-53894 1 Dulldusk 1 Phpfilemanager 2026-06-17 N/A 9.8 CRITICAL
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.
CVE-2023-4094 1 Fujitsu 1 Arconte Aurea 2026-06-17 N/A 6.5 MEDIUM
ARCONTE Aurea's authentication system, in its 1.5.0.0 version, could allow an attacker to make incorrect access requests in order to block each legitimate account and cause a denial of service. In addition, a resource has been identified that could allow circumventing the attempt limit set in the login form.
CVE-2023-49340 2026-06-17 N/A 9.8 CRITICAL
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.
CVE-2023-41900 2 Debian, Eclipse 2 Debian Linux, Jetty 2026-06-17 N/A 3.5 LOW
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides to revoke an already authenticated user, then the current request will still treat the user as authenticated. The authentication is then cleared from the session and subsequent requests will not be treated as authenticated. So a request on a previously authenticated session could be allowed to bypass authentication after it had been rejected by the `LoginService`. This impacts usages of the jetty-openid which have configured a nested `LoginService` and where that `LoginService` will is capable of rejecting previously authenticated users. Versions 9.4.52, 10.0.16, and 11.0.16 have a patch for this issue.
CVE-2023-41862 2026-06-17 N/A 5.3 MEDIUM
Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0.
CVE-2023-24890 1 Microsoft 1 Onedrive 2026-06-17 N/A 6.5 MEDIUM
Microsoft OneDrive for iOS Security Feature Bypass Vulnerability
CVE-2022-45860 1 Fortinet 2 Fortinac, Fortinac-f 2026-06-17 N/A 5.3 MEDIUM
A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registration page may allow an unauthenticated attacker to perform password spraying attacks with an increased chance of success.
CVE-2022-43400 1 Siemens 1 Siveillance Video Mobile Server 2026-06-17 N/A 9.8 CRITICAL
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile server component of affected applications improperly handles the log in for Active Directory accounts that are part of Administrators group. This could allow an unauthenticated remote attacker to access the application without a valid account.