A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
Volume of CVEs assigned to CWE-294 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
239 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-23397CRITICAL Microsoft Outlook Elevation of Privilege Vulnerability | Mar 14, 2023 | 9.8 | 96 | YES | NO |
CVE-2017-3191CRITICAL D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remot | Dec 16, 2017 | 9.8 | 61 | NO | NO |
CVE-2023-49231CRITICAL An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token. | Mar 29, 2024 | 9.8 | 48 | NO | NO |
CVE-2026-28564CRITICAL Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB.
REST Basic Authentication Accepts Stale Cached Credentials
This issue affe | Jul 10, 2026 | 9.8 | 42 | NO | NO |
CVE-2017-6823HIGH Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. | Mar 12, 2017 | 8.8 | 42 | NO | YES |
CVE-2026-11856CRITICAL Successfully using libcurl to do a transfer to a specific HTTP origin
(`hostA`) with **Digest** authentication and then changing the origin to a
different one (`hostB`) for a secon | Jul 3, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-8927CRITICAL When reusing a libcurl handle for sequential transfers driven by
environment-variable proxy configuration, libcurl fails to clear the proxy
authentication state between requests. S | Jul 3, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-56453CRITICAL HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses b | Jul 16, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-51597CRITICAL MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate a | Jul 9, 2026 | 9.1 | 37 | NO | NO |
CVE-2022-29593MEDIUM relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/aut | Jul 14, 2022 | 5.9 | 37 | NO | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.