Vulnerabilities (CVE)

Filtered by CWE-294
Total 232 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-49595 1 Dell 1 Wyse Management Suite 2026-06-17 N/A 7.6 HIGH
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
CVE-2024-46041 2026-06-17 N/A 8.8 HIGH
IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.
CVE-2024-45244 1 Hyperledger 1 Fabric 2026-06-17 N/A 5.3 MEDIUM
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
CVE-2024-43099 2026-06-17 N/A 8.8 HIGH
The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a session key is utilized to maintain security. However, if an attacker captures this session key, they can inject traffic into an ongoing authenticated session. To successfully achieve this, the attacker also needs to spoof both the IP address and MAC address of the originating host which is typical of a session-based attack.
CVE-2024-40715 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 7.7 HIGH
A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.
CVE-2024-3982 1 Hitachienergy 1 Microscada X Sys600 2026-06-17 N/A 8.2 HIGH
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
CVE-2024-39081 1 Jktyre 1 Smart Tyre Car \& Bike 2026-06-17 N/A 4.2 MEDIUM
An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications.
CVE-2024-38890 1 Horizoncloud 1 Caterease 2026-06-17 N/A 8.4 HIGH
An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.
CVE-2024-38823 2026-06-17 N/A 2.7 LOW
Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
CVE-2024-38438 1 Dlink 2 Dsl-225, Dsl-225 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link - CWE-294: Authentication Bypass by Capture-replay
CVE-2024-38284 2026-06-17 N/A N/A
Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a replay attack to replicate calls.
CVE-2024-38272 1 Google 1 Nearby 2026-06-17 N/A 4.3 MEDIUM
There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quick Share or above
CVE-2024-37016 2026-06-17 N/A 6.8 MEDIUM
Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach.
CVE-2024-36250 1 Mattermost 1 Mattermost Server 2026-06-17 N/A 3.1 LOW
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
CVE-2024-34065 1 Strapi 1 Strapi 2026-06-17 N/A 7.1 HIGH
Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass authentication mechanisms and retrieve the 3rd party tokens. The attack requires user interaction (one click). Unauthenticated attackers can leverage two vulnerabilities to obtain an 3rd party token and the bypass authentication of Strapi apps. Users should upgrade @strapi/plugin-users-permissions to version 4.24.2 to receive a patch.
CVE-2024-29851 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 7.2 HIGH
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
CVE-2024-29850 1 Veeam 1 Veeam Backup \& Replication 2026-06-17 N/A 8.8 HIGH
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
CVE-2024-22066 1 Zte 8 Zxr10 160, Zxr10 160 Firmware, Zxr10 1800-2s and 5 more 2026-06-17 N/A 7.5 HIGH
There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated attacker could use the vulnerability to obtain sensitive information about the device.
CVE-2024-12839 2026-06-17 N/A 8.8 HIGH
The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains this signature can use it to log into the system with any device.
CVE-2024-12137 2026-06-17 N/A 7.6 HIGH
Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. This issue affects ANKA JPD-00028: before V.01.01.