Skip to main content

CWE archive

CWE-294 CVEs

Programmatic archive

240 CVEs tagged with CWE-29435 Critical, 111 High, 83 Medium, 11 Low, 0 Unrated.

CVE-2026-15614

Published Jul 23, 2026

Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s validity window.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47133

Published Jul 20, 2026

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the on-disk SQLite policy store (`/Libr…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16083

Published Jul 18, 2026

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webh…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-56453

Published Jul 16, 2026

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35141

Published Jul 16, 2026

HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35149

Published Jul 16, 2026

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by inter…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57574

Published Jul 10, 2026

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthSe…

CVSS 7.4 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-55370

Published Jul 10, 2026

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verification accepted a successfully used TOTP code again while t…

CVSS 6.4 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-28564

Published Jul 10, 2026

Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue aff…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-51597

Published Jul 9, 2026

MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54783

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature veri…

CVSS 7.4 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-54779

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because…

CVSS 5.9 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-26232

Published Jul 3, 2026

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
26.1

CVE-2026-20779

Published Jul 3, 2026

Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication…

CVSS 7.1 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-8927

Published Jul 3, 2026

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests.…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-11856

Published Jul 3, 2026

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a seco…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-44946

Published Jun 30, 2026

A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in t…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49319

Published Jun 25, 2026

Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rollin…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56130

Published Jun 25, 2026

"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expira…

CVSS 2.0 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-55759

Published Jun 24, 2026

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-In hand…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47341

Published Jun 19, 2026

Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry.…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34021

Published Jun 15, 2026

The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic pro…

CVSS 8.6 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-41000

Published Jun 11, 2026

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of Usern…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-49322

Published May 29, 2026

Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read access to the i…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 240 CVEsPage 1 of 10