CWE-294 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-294 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2023-23397Microsoft Outlook Elevation of Privilege Vulnerability97.2%심각9.8CVE-2026-69676Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute…1.2%높음8.8CVE-2026-54148http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0…0.6%높음8.1CVE-2026-87119Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscri…0.6%높음8.2CVE-2026-55250Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-…0.6%높음8.7CVE-2026-86219Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication respon…0.5%미평가CVE-2026-84003Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allow…0.4%높음7.4CVE-2026-90997A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in r…0.4%높음7.4
전체 목록
23건
CVE-2026-94112mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay…0.4%높음7.6
CVE-2026-73311XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtai…0.4%심각9.1
CVE-2026-82379Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE di…0.4%높음7.7
CVE-2026-73636Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.…0.4%높음8.1
CVE-2026-73312XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh t…0.4%심각9.1
CVE-2026-75907The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-…0.4%높음7.5
CVE-2026-69206Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection re…0.3%보통5.9
CVE-2026-100834http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 a…0.3%높음8.2
CVE-2026-103655MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a vali…0.3%심각9.3
CVE-2026-73443On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attac…0.3%보통5.3
CVE-2026-88278GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, all…0.3%심각9.8
CVE-2022-51016PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cann…0.2%보통5.3
CVE-2026-77967The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying it…0.2%높음8.6
CVE-2026-75034A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-4…0.2%높음7.4
CVE-2026-45720Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.…0.1%높음7.0
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.