Vulnerabilities (CVE)

Filtered by CWE-294
Total 232 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-59023 1 Powerdns 1 Recursor 2026-06-17 N/A 8.2 HIGH
Crafted delegations or IP fragments can poison cached delegations in Recursor.
CVE-2025-56448 1 Positron 2 Px360bt, Px360bt Firmware 2026-06-17 N/A 6.8 MEDIUM
The Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security. The alarm system does not properly rotate or invalidate used codes, allowing repeated reuse of captured transmissions. This exposes users to significant security risks, including vehicle theft and loss of trust in the alarm's anti-cloning claims.
CVE-2025-54810 2026-06-17 N/A 8.0 HIGH
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a proprietary protocol on TCP port 1069 to perform management operations such as modifying system properties. The user management functionality handles sensitive data such as registered usernames and passwords over an unencrypted channel, allowing an adjacent attacker to intercept valid credentials to gain access to the device.
CVE-2025-49752 1 Microsoft 1 Azure Bastion Developer 2026-06-17 N/A 10.0 CRITICAL
Azure Bastion Elevation of Privilege Vulnerability
CVE-2025-48012 1 One Time Password Project 1 One Time Password 2026-06-17 N/A 4.8 MEDIUM
Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 before 1.3.0.
CVE-2025-47706 1 Miniorange 1 Miniorange 2fa 2026-06-17 N/A 4.8 MEDIUM
Authentication Bypass by Capture-replay vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Remote Services with Stolen Credentials.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.7.0, from 5.0.0 before 5.2.0.
CVE-2025-46815 1 Zitadel 1 Zitadel 2026-06-17 N/A 8.0 HIGH
The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for authentication, known as idp intents. Following a successful idp intent, the client receives an id and token on a predefined URI. These id and token can then be used to authenticate the user or their session. However, prior to versions 3.0.0, 2.71.9, and 2.70.10, it was possible to exploit this feature by repeatedly using intents. This allowed an attacker with access to the application’s URI to retrieve the id and token, enabling them to authenticate on behalf of the user. It's important to note that the use of additional factors (MFA) prevents a complete authentication process and, consequently, access to the ZITADEL API. Versions 3.0.0, 2.71.9, and 2.70.10 contain a fix for the issue. No known workarounds other than upgrading are available.
CVE-2025-40807 1 Siemens 1 Gridscale X Prepay 2026-06-17 N/A 6.3 MEDIUM
A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay of authentication tokens. This could allow an authenticated but already locked-out user to establish still valid user sessions.
CVE-2025-36593 1 Dell 1 Openmanage Network Integration 2026-06-17 N/A 8.8 HIGH
Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access could potentially exploit this vulnerability to forge a valid protocol accept message in response to a failed authentication request.
CVE-2025-35061 1 Newforma 1 Project Center 2026-06-17 N/A 5.9 MEDIUM
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the user-configured NIX service account.
CVE-2025-35058 1 Newforma 1 Project Center 2026-06-17 N/A 5.9 MEDIUM
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the customer-configured NIX service account.
CVE-2025-35057 1 Newforma 1 Project Center 2026-06-17 N/A 5.3 MEDIUM
Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the NIX service account.
CVE-2025-30201 1 Wazuh 1 Wazuh 2026-06-17 N/A 7.7 HIGH
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various agent configuration settings, potentially leading NTLM relay attacks that would result privilege escalation and remote code execution. This issue has been patched in version 4.13.0.
CVE-2025-30072 1 Tiiwee 2 Twx1hakv2, Twx1hakv2 Firmware 2026-06-17 N/A 7.6 HIGH
Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.
CVE-2025-1887 2026-06-17 N/A N/A
SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker.
CVE-2025-13777 2026-06-17 N/A 8.3 HIGH
Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.
CVE-2024-8260 2 Microsoft, Openpolicyagent 2 Windows, Open Policy Agent 2026-06-17 N/A 6.1 MEDIUM
A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.
CVE-2024-5249 1 Perforce 1 Akana Api 2026-06-17 N/A 5.4 MEDIUM
In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
CVE-2024-52534 1 Dell 1 Elastic Cloud Storage 2026-06-17 N/A 5.4 MEDIUM
Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
CVE-2024-4009 1 Abb 10 2tma310010b0001, 2tma310010b0001 Firmware, 2tma310010b0003 and 7 more 2026-06-17 N/A 9.2 CRITICAL
Replay Attack in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to capture/replay KNX telegram to local KNX Bus-System