Skip to main content

CWE archive

CWE-592 CVEs

Programmatic archive

24 CVEs tagged with CWE-5928 Critical, 9 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2026-43512

Published May 12, 2026

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2023-30971

Published Dec 19, 2025

Gotham Gaia application was found to be exposing multiple unauthenticated endpoints.

CVSS 6.8 · Medium

CVE-2024-42759

Published Sep 9, 2024

An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38884

Published Aug 2, 2024

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attac…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14910

Published Dec 5, 2019

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14909

Published Dec 4, 2019

A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10933

Published Oct 17, 2018

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication,…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.9
Public PoC observed

CVE-2018-14643

Published Sep 21, 2018

An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on mach…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-8616

Published Aug 1, 2018

A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. Thi…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-10847

Published Jul 30, 2018

prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same acr…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2650

Published Jul 27, 2018

It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. J…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12164

Published Jul 26, 2018

A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1085

Published Jun 15, 2018

openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled. Quotations around the valu…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-2684

Published Feb 22, 2017

Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2367

Published Jul 19, 2014

The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted cal…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4688

Published Dec 31, 2012

The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1