Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified HIGH 8.7
CVE-2024-1609

In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.

No fix yet
Fix from $1,950 2024-12-25
Unclassified HIGH 8.1
CVE-2023-31279

The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the ow…

Mitigation only
Fix from $1,950 2024-12-21
Vaultwarden HIGH 7.5
CVE-2024-56335

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable…

Fix: 1.32.7+
Fix from $1,950 2024-12-20
Unclassified HIGH 8.9
CVE-2024-56329

Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jet…

Patch available
Fix from $1,950 2024-12-20
Unclassified CRITICAL 9.8
CVE-2024-12287

The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the …

Mitigation only
Fix from $2,300 2024-12-18
Unclassified CRITICAL 9.8
CVE-2024-1610

In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.

Mitigation only
Fix from $2,300 2024-12-18
Unclassified HIGH 7.1
CVE-2024-21543

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the syste…

Patch available
Fix from $1,950 2024-12-13
Opensearch Data Prepper MEDIUM 6.9
CVE-2024-55886

OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes data at scale. A vulnerabili…

Fix: 2.10.2+
Fix from $1,600 2024-12-12
Unclassified HIGH 8.1
CVE-2024-10111

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.…

Mitigation only
Fix from $1,950 2024-12-12
Unclassified CRITICAL 9.8
CVE-2024-11015

The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to the '…

Mitigation only
Fix from $2,300 2024-12-12
Glpi MEDIUM 5.3
CVE-2024-50339EPSS 20%

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve…

Fix: 10.0.17+
Fix from $1,600 2024-12-12
Windows 10 1809 HIGH 7.8
CVE-2024-49076

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

Fix: 10.0.17763.6659 / 10.0.19044.5247+
Fix from $1,950 2024-12-12
Opencti HIGH 8.1
CVE-2024-45404

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist,…

Fix: 6.2.18+
Fix from $1,950 2024-12-12
Glpi HIGH 7.2
CVE-2024-47761

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the s…

Fix: 10.0.17+
Fix from $1,950 2024-12-11
Unclassified MEDIUM 5.3
CVE-2024-10511

CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local network repeat…

No fix yet
Fix from $1,600 2024-12-11
Unclassified HIGH 8.8
CVE-2024-0130

NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending…

No fix yet
Fix from $1,950 2024-12-06
Qts CRITICAL 9.1
CVE-2024-48859

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could al…

Mitigation only
Fix from $2,300 2024-12-06
Unclassified HIGH 8.1
CVE-2024-11293

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Si…

Mitigation only
Fix from $1,950 2024-12-04
Ozone HIGH 8.1
CVE-2024-45106

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate t…

Mitigation only
Fix from $1,950 2024-12-03
Unclassified CRITICAL 9.2
CVE-2024-53990

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any…

Patch available
Fix from $2,300 2024-12-02
Mdm9206 Firmware HIGH 7.8
CVE-2018-11952

An image with a version lower than the fuse version may potentially be booted lead to improper authentication.

No fix yet
Fix from $1,950 2024-11-26
Mdm9206 Firmware HIGH 7.8
CVE-2016-10394

Initial xbl_sec revision does not have all the debug policy features and critical checks.

No fix yet
Fix from $1,950 2024-11-26
Remote Desktop Manager MEDIUM 5.4
CVE-2024-11671

Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authentica…

Fix: 2024.3.18.0+
Fix from $1,600 2024-11-25
Unclassified MEDIUM 6.7
CVE-2022-33862

IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.

Mitigation only
Fix from $1,600 2024-11-25
Unclassified HIGH 8.1
CVE-2024-45369

The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and authorized resource.

Mitigation only
Fix from $1,950 2024-11-22
Cam V3 Firmware HIGH 7.5
CVE-2024-6248

Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to…

Fix: 4.36.11.8391+
Fix from $1,950 2024-11-22
P6101c Firmware HIGH 7.5
CVE-2024-11494

**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could …

No fix yet
Fix from $1,950 2024-11-20
Unclassified CRITICAL 9.8
CVE-2024-47533

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability s…

Patch available
Fix from $2,300 2024-11-18
Nextcloud Server MEDIUM 5.4
CVE-2024-52518

Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would b…

Fix: 28.0.12 / 29.0.9+
Fix from $1,600 2024-11-15
Central Authentication Service CRITICAL 9.8
CVE-2024-11209

A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the compo…

No fix yet
Fix from $2,300 2024-11-14