Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Unclassified HIGH 7.5
CVE-2024-51996

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, …

Patch available
Fix from $1,950 2024-11-13
Windows 10 1507 HIGH 8.8
CVE-2024-49039 KEVEPSS 14%

Windows Task Scheduler Elevation of Privilege Vulnerability

Fix: 10.0.10240.20826 / 10.0.14393.7515+
Fix from $1,950 2024-11-12
Unclassified HIGH 8.1
CVE-2024-51997

Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) tok…

Mitigation only
Fix from $1,950 2024-11-08
Unclassified HIGH 7.4
CVE-2024-10963

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attacker…

Patch available
Fix from $1,950 2024-11-07
Super Socializer HIGH 8.1
CVE-2024-9946

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versi…

Fix: 7.14+
Fix from $1,950 2024-11-06
Social Login HIGH 8.1
CVE-2024-10020

The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is …

Fix: 1.1.36+
Fix from $1,950 2024-11-06
Waybox Pro Firmware HIGH 8.8
CVE-2023-29117

Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.

Fix: 2.1.1.0_jb3vu096a+
Fix from $1,950 2024-11-05
Woocommerce Social Login HIGH 8.1
CVE-2024-10114

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due t…

Fix: 2.7.8+
Fix from $1,950 2024-11-05
Loginizer HIGH 8.1
CVE-2024-10097

The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This …

Fix: 1.9.3+
Fix from $1,950 2024-11-05
Unclassified MEDIUM 5.3
CVE-2024-10620

A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list…

Mitigation only
Fix from $1,600 2024-11-01
Firefox Focus MEDIUM 6.5
CVE-2024-10474

Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing s…

Fix: 132.0+
Fix from $1,600 2024-10-29
1 Click Login\ CRITICAL 9.8
CVE-2024-50478

Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue a…

Mitigation only
Fix from $2,300 2024-10-28
Autolab HIGH 8.8
CVE-2024-49376

Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0.…

Patch available
Fix from $1,950 2024-10-25
Whatsup Gold HIGH 7.5
CVE-2024-7763

In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credenti…

Fix: 24.0+
Fix from $1,950 2024-10-24
Unclassified HIGH 8.1
CVE-2024-10327

A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextE…

Mitigation only
Fix from $1,950 2024-10-24
Profilepress CRITICAL 9.8
CVE-2024-9947

The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insuffi…

Fix: 4.11.2+
Fix from $2,300 2024-10-23
Woocommerce Order Proposal HIGH 7.2
CVE-2024-9927

The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all versions up to and including 2.0.…

Fix: 2.0.6+
Fix from $1,950 2024-10-23
Ddmq HIGH 7.5
CVE-2024-10173

A vulnerability has been found in didi DDMQ 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the compone…

No fix yet
Fix from $1,950 2024-10-20
Quay MEDIUM 5.3
CVE-2024-9683

A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a…

Mitigation only
Fix from $1,600 2024-10-17
Unclassified HIGH 8.8
CVE-2023-22650

A vulnerability has been identified in which Rancher does not automatically clean up a user which has been deleted from the configured authentication…

Mitigation only
Fix from $1,950 2024-10-16
Solr CRITICAL 9.8
CVE-2024-45216EPSS 91%

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authen…

Fix: 8.11.4 / 9.7.0+
Fix from $2,300 2024-10-16
Unclassified CRITICAL 9.8
CVE-2020-36832

The Ultimate Membership Pro plugin for WordPress is vulnerable to Authentication Bypass in versions between, and including, 7.3 to 8.6. This makes it…

Mitigation only
Fix from $2,300 2024-10-16
Dataverse HIGH 8.8
CVE-2024-38139

Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

Patch available
Fix from $1,950 2024-10-15
Unclassified HIGH 8.7
CVE-2024-47080

matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `Ma…

Patch available
Fix from $1,950 2024-10-15
Commerce HIGH 8.8
CVE-2024-45148

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could resul…

Mitigation only
Fix from $1,950 2024-10-10
Commerce CRITICAL 9.8
CVE-2024-45115

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could resul…

Mitigation only
Fix from $2,300 2024-10-10
Windows Server 2008 CRITICAL 9.0
CVE-2024-38124

Windows Netlogon Elevation of Privilege Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $2,300 2024-10-08
Unclassified CRITICAL 9.8
CVE-2024-41798

A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative…

Mitigation only
Fix from $2,300 2024-10-08
Discourse HIGH 8.2
CVE-2024-45051

Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based res…

Fix: 3.3.2 / 3.4.0+
Fix from $1,950 2024-10-07
Lif Authentication Server HIGH 8.1
CVE-2024-47768

Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery …

Fix: 1.7.3+
Fix from $1,950 2024-10-04