Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A
Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability,
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electron
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active
Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vu
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex X
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a n
Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att
Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier all
FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause w
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access
Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit th
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVu
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-pro
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless ent
A weak authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, they c
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This is
Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 vers
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year al
Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcyc
A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature valid
Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically register
Frequently Asked Questions
What is CWE-1390?
CWE-1390 (CWE-1390) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1390?
There are 31 CVE records associated with CWE-1390 in our database. Of these, 11 are critical severity, 12 are high severity, and 6 are medium severity.
How can I protect against CWE-1390 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1390 using AI-powered security agents.
Detect CWE-1390 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1390 vulnerabilities across your infrastructure.
Get Started