Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can inter
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track
Crafted zones can lead to increased incoming network traffic.
OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Bas
Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and the
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow a
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of th
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown fun
Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year al
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-ti
A vulnerability has been found in DJI Mavic Mini, Air, Spark and Mini SE up to 01.00.0500. Affected by this vulnerabilit
A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This affects an unknown par
HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to interce
The Micca KE700 system contains flawed resynchronization logic and is vulnerable to replay attacks. This attack requires
The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between t
"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie
Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.
Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previous
Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Ac
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources
Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject
Frequently Asked Questions
What is CWE-294?
CWE-294 (CWE-294) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-294?
There are 76 CVE records associated with CWE-294 in our database. Of these, 10 are critical severity, 24 are high severity, and 28 are medium severity.
How can I protect against CWE-294 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-294 using AI-powered security agents.
Detect CWE-294 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-294 vulnerabilities across your infrastructure.
Get Started