VulnSea

CWE-294

CVEs classified under CWE-294, newest first.

45 CVEsRSS

CVE-2026-94112Medium· 6.8
2d ago

mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window

mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode …

Sunlitmayswind · ezBookkeepingEPSS 0.23%via NVD
CVE-2026-54148High· 8.1
4d ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the …

Twilighthttp4k · http4kEPSS 0.33%via NVD
CVE-2026-45720High· 7.0
5d ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state ope…

Twilightsiderolabs · omniEPSS 0.11%via NVD
CVE-2026-90997High· 7.4
5d ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vuln…

TwilightKeycloak · keycloak-servicesEPSS 0.40%via NVD
CVE-2026-73443Medium· 4.7
6d ago

On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement …

On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement …

SunlitArista Networks · EOSEPSS 0.27%via NVD
CVE-2026-69206Medium· 5.9
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastNc plus one instead of the highest nonce-count value it has accepted. When a legitimate client sends noncontiguous nc…

Sunlithttp4s · http4sEPSS 0.33%via NVD
CVE-2026-88278Critical· 9.8
1w ago

GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

MidnightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.27%via CVEORG
CVE-2026-55250High· 8.7
2w ago

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-perf…

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-perf…

Twilightmacropay-solutions · maravel-frameworkEPSS 0.55%via NVD
CVE-2026-84003High· 7.4
2w ago

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

Twilightmicrosoft · azure/msal-nodeEPSS 0.43%via NVD
CVE-2026-69676High· 8.8
2w ago

Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.

Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via NVD
CVE-2026-73312High· 7.4PoC
2w ago

XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired

XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark tokens as consumed when the parent access token has expired. Attackers ca…

Midnightxenforo · xenforoEPSS 0.35%via NVD
CVE-2026-73311High· 7.4PoC
2w ago

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate …

Midnightxenforo · xenforoEPSS 0.37%via NVD
CVE-2022-51016Medium· 6.1
2w ago

PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login token

PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login token. An attacker who captures a valid…

Sunlitpmmp · PocketMine-MPEPSS 0.23%via NVD
CVE-2026-86219Critical· 9.8
2w ago

Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares …

Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares …

MidnightEPSS 0.49%via NVD
CVE-2026-75034High· 7.4
2w ago

A flaw was found in Rancher Manager

A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. I…

Twilightsuse · rancherEPSS 0.20%via NVD
CVE-2026-53636Medium· 4.7
2w ago

Open edX Platform enables the authoring and delivery of online learning at any scale

Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX LMS platform's LTI (Learning Tools Interoperability) Provider imp…

SunlitEPSS 0.17%via NVD
CVE-2026-84306Medium· 6.5
3w ago

Filament is a collection of full-stack components for accelerated Laravel development

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthentication.php uses AppAuthentication::verifyCode() with a used-cod…

Sunlitfilament · filament/filamentEPSS 0.36%via NVD
CVE-2026-82470Medium· 5.4
3w ago

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to b…

SunlitEPSS 0.24%via NVD
CVE-2025-61479High· 7.5
3w ago

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected in…

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected in…

TwilightEPSS 0.24%via NVD
CVE-2025-61480High· 7.5
3w ago

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.

TwilightEPSS 0.13%via NVD
CVE-2026-46369High· 7.5
3w ago

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative t…

Twilightnimiq-blockchain · nimiq-blockchainEPSS 0.39%via NVD
CVE-2026-73136High· 7.5
1mo ago

Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithM…

Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. MPP.Methods.Tempo normally binds a settled TIP-20 TransferWithM…

Twilightzenhive · machine_payments_protocolEPSS 0.42%via NVD
CVE-2026-67581High· 7.5
1mo ago

Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and ma…

Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled on-chain transfer. MPP.Methods.EVM.verify/2 accepts a transaction-hash credential and ma…

Twilightzenhive · machine_payments_protocolEPSS 0.41%via NVD
CVE-2026-55088Medium· 6.8
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTra…

Sunlitep_etherpad-lite · ep_etherpad-liteEPSS 0.36%via NVD
CVE-2026-50575High· 7.7
1mo ago

BetterDesk is a remote desktop management solution

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Ve…

TwilightEPSS 0.21%via NVD
CVE-2026-62911High· 8.0PoC
1mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 1.3%via CVEORG
GHSA-wg23-69c2-gjc8Critical
1mo ago

Craft CMS: Passkey login accepts replayed WebAuthn assertions

Craft CMS: Passkey login accepts replayed WebAuthn assertions

Midnightcraftcms · craftcms/cmsvia GHSA
CVE-2026-16083Medium· 5.3
2mo ago

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by …

SunlitEPSS 0.72%via NVD
CVE-2026-57574None
2mo ago

Misskey is an open source, federated social media platform

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows …

SunlitEPSS 0.55%via NVD
CVE-2026-55370Medium· 6.4
2mo ago

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verification accepted a successfully used TOTP code again while the code remained inside the RFC 6238 acceptance window bec…

SunlitEPSS 0.34%via NVD
CWE-294 vulnerabilities (CVEs) · VulnSea