CWE-294: CWE-294
Yearly Trend
Top Affected Vendors
All CWE-294 CVEs (52)
CVE-2025-49752 is an elevation of privilege vulnerability in Azure Bastion that allows authenticated attackers to gain unauthorized administrative acc...
Nov 20, 2025This vulnerability in the PF-50 1.2 keyfob of the PGST PG107 Alarm System allows attackers to perform code replay attacks, enabling unauthorized acces...
Feb 11, 2026The D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on its 433 MHz sensor communication channel. Attackers within RF r...
Jan 12, 2026A vulnerability in hexo-theme-matery's verifyPassword function allows attackers to bypass authentication and access password-protected pages without v...
Apr 19, 2024An authentication bypass vulnerability in Stilog Visual Planning 8 allows unauthenticated attackers to obtain administrative API tokens. This affects ...
Mar 29, 2024CVE-2023-30909 is a critical authentication bypass vulnerability in HPE OneView APIs that allows remote attackers to bypass authentication mechanisms ...
Sep 14, 2023This vulnerability allows attackers to bypass authentication in the Answer software by capturing and replaying authentication tokens. It affects all A...
Mar 21, 2023CVE-2022-29334 is an authentication bypass vulnerability in H v1.0 that allows attackers to gain unauthorized access via session replay attacks. This ...
May 24, 2022CVE-2018-17932 affects JUUKO K-800 industrial control devices, allowing attackers to replay commands and forge malicious commands. This could enable u...
Nov 2, 2020This vulnerability allows attackers within wireless range to replay captured Zigbee packets with manipulated sequence numbers, bypassing anti-replay p...
Apr 15, 2025GreaterWMS versions up to 2.1.49 contain an authentication bypass vulnerability in the /staff route that allows unauthenticated remote attackers to ac...
Feb 24, 2025Dell OpenManage Network Integration versions before 3.8 contain a RADIUS authentication bypass vulnerability where attackers can replay captured proto...
Jun 30, 2025The IoT Haat Smart Plug IH-IN-16A-S v5.16.1 has an authentication bypass vulnerability where attackers can replay captured authentication data to gain...
Oct 7, 2024This vulnerability allows session hijacking in industrial control systems by capturing session keys used between host PCs and PLCs. Attackers can inje...
Sep 13, 2024The Meross MSH30Q thermostat's radio frequency communication protocol is vulnerable to replay attacks, allowing attackers to record legitimate command...
Jan 23, 2024CVE-2022-31277 is a replay attack vulnerability in Xiaomi Lamp 1 smart bulbs that allows attackers to capture and reuse authentication requests. This ...
Jun 16, 2022This vulnerability allows remote attackers to execute arbitrary code on a user's system when they launch a replay file from an untrusted source in Wor...
May 26, 2022This vulnerability in SaltStack Salt allows attackers to replay job publishes and file server responses, potentially causing minions to execute outdat...
Mar 29, 2022This vulnerability allows a local attacker to bypass authentication in Caterease Software by performing a capture-replay attack due to insufficient pr...
Aug 2, 2024This CVE describes an authentication bypass vulnerability in multiple Mitsubishi Electric MELSEC industrial control system (ICS) products. Attackers c...
Apr 1, 2022Laravel Fortify before version 1.11.1 has a TOTP (Time-based One-Time Password) vulnerability where one-time codes can be reused within a short time w...
Feb 24, 2022Cognex In-Sight Explorer and In-Sight Camera Firmware transmit user credentials over unencrypted TCP port 1069, allowing adjacent attackers to interce...
Sep 18, 2025This vulnerability in ZITADEL's Session API allows attackers to repeatedly use idp intents to steal authentication tokens. Attackers with access to th...
May 6, 2025This vulnerability allows attackers to bypass authentication in Veeam Backup & Replication Enterprise Manager by performing a Man-in-the-Middle attack...
Nov 7, 2024This authentication bypass vulnerability in Elfatek Elektronics ANKA JPD-00028 allows attackers to hijack user sessions by capturing and replaying aut...
Mar 19, 2025Dell Wyse Management Suite versions 4.4 and earlier contain an authentication bypass vulnerability where attackers can replay captured authentication ...
Nov 26, 2024CVE-2024-22066 is an authentication bypass vulnerability in ZTE ZXR10 ZSR V2 routers that allows authenticated attackers to escalate privileges and ac...
Oct 29, 2024This vulnerability allows attackers to bypass security controls in the Kerui W18 Alarm System by recording and replaying 433MHz signals from the keyfo...
May 24, 2023CVE-2023-31762 is a code replay vulnerability in the Digoo DG-HAMB Smart Home Security System transmitter that allows attackers to capture and replay ...
May 24, 2023CVE-2021-22640 allows an attacker to decrypt the Ovarro TBox login password by capturing communication and performing brute-force attacks, potentially...
Jul 28, 2022This vulnerability allows unauthenticated attackers to bypass authentication on SICAM T devices by capturing and replaying challenge-response pairs. A...
May 20, 2022This vulnerability in Apache Spark allows attackers to recover full encryption keys from RPC connections using a flawed mutual authentication protocol...
Mar 10, 2022This vulnerability allows an attacker to exploit Windows NTLM authentication to elevate privileges on affected systems. It affects Windows operating s...
Jun 8, 2021This vulnerability allows an on-path attacker between engineering software and SIMATIC S7-1200 controllers to replay previously captured commands, pot...
Oct 14, 2025This CVE describes an authentication bypass vulnerability in a 2017 Hyundai vehicle model where attackers can capture and replay legitimate authentica...
Sep 3, 2023This CVE describes an authentication bypass vulnerability in phpMyFAQ where attackers can replay captured authentication data to gain unauthorized acc...
Apr 5, 2023This vulnerability in Veeam Backup Enterprise Manager allows authenticated high-privileged users to capture the NTLM hash of the Enterprise Manager se...
May 22, 2024This CVE describes an authentication bypass vulnerability in Strapi's users-permissions plugin. By combining an open redirect with session tokens sent...
Jun 12, 2024This CVE describes a privilege escalation vulnerability in VMware vSphere where a malicious actor with Guest Operation Privileges in a target virtual ...
Aug 31, 2023CVE-2021-26824 is an authentication bypass vulnerability in DM FingerTool v1.19 on DM PD065 Secure USB devices. It allows local attackers to replay au...
Jul 26, 2021The Positron PX360BT car alarm system is vulnerable to replay attacks due to improper rolling code implementation, allowing attackers to reuse capture...
Sep 15, 2025This vulnerability allows attackers to bypass authentication on Mengshen Wireless Door Alarm M70 devices by capturing and replaying network traffic. A...
Jul 15, 2024LakeFS's S3 gateway fails to validate timestamps in authenticated requests, allowing replay attacks. Attackers who capture valid signed requests can r...
Jan 15, 2026The D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is vulnerable to RF jamming attacks on its 433 MHz alarm sensor channel. Attackers within radio freq...
Jan 12, 2026Gridscale X Prepay versions before V4.2.1 are vulnerable to authentication token capture-replay attacks. This allows authenticated users who should be...
Dec 9, 2025CVE-2025-35061 is an authentication relay vulnerability in Newforma Info Exchange (NIX) that allows unauthenticated attackers to force the system to m...
Oct 9, 2025CVE-2025-35058 is an authentication bypass vulnerability in Newforma Info Exchange (NIX) that allows unauthenticated remote attackers to force the NIX...
Oct 9, 2025This vulnerability allows attackers to replay SAML tokens in Akana API Platform, potentially enabling unauthorized access to protected resources. Orga...
Jul 30, 2024This vulnerability in Newforma Info Exchange (NIX) allows remote, unauthenticated attackers to force the NIX server to initiate SMB connections to att...
Oct 9, 2025This vulnerability allows attackers to bypass timestamp validation in Hyperledger Fabric, potentially enabling transaction replay attacks or manipulat...
Aug 25, 2024About CWE-294 (CWE-294)
Our database tracks 52 CVEs classified as CWE-294, with 11 rated critical and 29 rated high severity. The average CVSS score for CWE-294 vulnerabilities is 7.8.
External reference: View CWE-294 on MITRE CWE →
Monitor CWE-294 Vulnerabilities
Get alerted when new CWE-294 CVEs affect your infrastructure.
Start Monitoring Free