D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication chan
Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access contro
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/de
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authe
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize req
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authenticat
Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW
Crafted delegations or IP fragments can poison cached delegations in Recursor.
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized us
azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in
Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlRespon
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform unauthorized operations and access s
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attack
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted devi
Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative clo
OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported int
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive informati
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6,
A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-t
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither WebAut
Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDec
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac
Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and usern
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsAction
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multip
D3D Wi-Fi Home Security System ZX-G12 v2.1.17 is susceptible to RF jamming on the 433 MHz alarm sensor channel. An attac
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not
OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed
OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized even
OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attack
Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configuration
Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., L
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey
Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c vali
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verifi
A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured a
Frequently Asked Questions
What is CWE-294?
CWE-294 (CWE-294) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-294?
There are 76 CVE records associated with CWE-294 in our database. Of these, 10 are critical severity, 24 are high severity, and 28 are medium severity.
How can I protect against CWE-294 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-294 using AI-powered security agents.
Detect CWE-294 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-294 vulnerabilities across your infrastructure.
Get Started