CWE-304
33 CVEs • Abstraction: Base
Missing Critical Step in Authentication
The product implements an authentication technique, but it skips a step that weakens the technique.
CVEs (33)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID C...Show more |
The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all version...Show more |
2Infinispan Redhat4Data Grid InfinispanJboss Data Grid+1 moreJun 17, 2026 Dec 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of t...Show more |
2Infinispan Redhat4Data Grid InfinispanJboss Data Grid+1 moreJun 17, 2026 Dec 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permiss...Show more |
Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls un...Show more |
Metabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9 single sign on (SSO) users were able to do password resets on Metabase, which could allow a us...Show more |
The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged...Show more |
Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. |
1Lenze 3C520 Firmware C550 FirmwareC750 FirmwareJun 17, 2026 Jul 11, 2022 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowledge of the password. |
1Abacus 5Abacus Erp 2018 Abacus Erp 2019Abacus Erp 2020+2 moreJun 17, 2026 Apr 19, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15; v2021 versions...Show more |
Nextcloud is an open-source, self-hosted productivity platform. Prior to Nextcloud Server versions 20.0.13, 21.0.5, and 22.2.0, the Two-Factor Authentication wasn't enforced for pages marked as public. Any page marked as...Show more |
When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full ac...Show more |
1Suse 1Suse Linux Enterprise Server Nov 21, 2024 Jun 8, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12. |