CWE-294

CWE-294 · 7 records · 5 with a public proof-of-concept

Records the NVD classes under CWE-294, highest CVSS first.

  1. HIGH 8.1CVE-2026-77967public PoC

    The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a valid authentication va…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.7CVE-2026-82379public PoC

    Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or times…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-75907

    The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to a…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.8CVE-2026-94112public PoC

    mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple author…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.9CVE-2026-100834public PoC

    http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.0 defaults the nonceVerifier parameter of ServerFilters.DigestAuth and DigestAuthProvider to { true }, so every nonce is accepted regardless…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 4.7CVE-2026-73443

    On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefinit…

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-87119public PoC

    Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id, expiry, limits and sc…

    AI risk analysis on Exploit-DB.ai →