Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Commerce CRITICAL 9.8
CVE-2024-45115

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could resul…

Mitigation only
Fix from $2,300 2024-10-10
Windows Server 2008 CRITICAL 9.0
CVE-2024-38124

Windows Netlogon Elevation of Privilege Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $2,300 2024-10-08
Unclassified CRITICAL 9.8
CVE-2024-41798

A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative…

Mitigation only
Fix from $2,300 2024-10-08
Discourse HIGH 8.2
CVE-2024-45051

Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based res…

Fix: 3.3.2 / 3.4.0+
Fix from $1,950 2024-10-07
Lif Authentication Server HIGH 8.1
CVE-2024-47768

Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery …

Fix: 1.7.3+
Fix from $1,950 2024-10-04
Vigor3910 Firmware HIGH 8.8
CVE-2024-41589

DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.

Fix: after 4.3.2.6
Fix from $1,950 2024-10-03
Openid Connect Authentication HIGH 8.1
CVE-2024-47806

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing atta…

Fix: 4.355.v3a_fb_fca_b_96d4+
Fix from $1,950 2024-10-02
Openid Connect Authentication HIGH 8.1
CVE-2024-47807

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attack…

Fix: 4.355.v3a_fb_fca_b_96d4+
Fix from $1,950 2024-10-02
Authentik CRITICAL 9.0
CVE-2024-47070

authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login…

Fix: 2024.6.5 / 2024.8.3+
Fix from $2,300 2024-09-27
Unclassified MEDIUM 5.9
CVE-2024-47174

Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did…

Patch available
Fix from $1,600 2024-09-26
Gotenna Pro MEDIUM 5.4
CVE-2024-47125

The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your…

Fix: 2.0.3+
Fix from $1,600 2024-09-26
Unclassified HIGH 7.3
CVE-2024-45750

An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN …

Mitigation only
Fix from $1,950 2024-09-25
Meshtastic Firmware CRITICAL 9.8
CVE-2024-47078

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or p…

Fix: 2.5.1+
Fix from $2,300 2024-09-25
Purity\/\/fa CRITICAL 9.8
CVE-2024-0002

A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.

Fix: after 6.4.10
Fix from $2,300 2024-09-23
Nebulagraph Database CRITICAL 9.8
CVE-2024-47218

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.

Fix: after 3.8.0
Fix from $2,300 2024-09-22
Mautic MEDIUM 6.5
CVE-2022-25768

The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. …

Fix: 4.4.13 / 5.1.1+
Fix from $1,600 2024-09-18
Remedy Mid Tier CRITICAL 9.8
CVE-2024-34399

**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user ac…

Mitigation only
Fix from $2,300 2024-09-18
Unclassified HIGH 8.8
CVE-2024-41929

Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated at…

Mitigation only
Fix from $1,950 2024-09-18
Pt30x Sdi Firmware CRITICAL 9.1
CVE-2024-8956 KEVEPSS 61%

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authent…

Fix: 6.3.40+
Fix from $2,300 2024-09-17
Ipados MEDIUM 5.3
CVE-2024-44202

An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs m…

Fix: 18.0+
Fix from $1,600 2024-09-17
Ipados MEDIUM 5.3
CVE-2024-44127

This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. Private Browsing t…

Fix: 17.7+
Fix from $1,600 2024-09-17
Coldfusion HIGH 7.5
CVE-2024-45113

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. A…

Mitigation only
Fix from $1,950 2024-09-13
Factorytalk Batch View CRITICAL 9.8
CVE-2024-45823

CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across…

Mitigation only
Fix from $2,300 2024-09-12
Eclipse Dataspace Components HIGH 8.1
CVE-2024-8642

In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for…

Fix: 0.9.0+
Fix from $1,950 2024-09-11
Dynamics 365 Business Central CRITICAL 9.8
CVE-2024-38225

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2024-09-10
Spectrum CRITICAL 9.8
CVE-2023-37226

Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.

Fix: 4.6+
Fix from $2,300 2024-09-10
Veeam Backup \& Replication HIGH 7.8
CVE-2024-40713

A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication…

Fix: 12.2.0.334+
Fix from $1,950 2024-09-07
Music Station HIGH 8.8
CVE-2023-45038

An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise t…

Fix: 5.4.0+
Fix from $1,950 2024-09-06
Intrusion Prevention System Manager MEDIUM 5.3
CVE-2024-5956

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manage…

Mitigation only
Fix from $1,600 2024-09-05
Intrusion Prevention System Manager HIGH 7.5
CVE-2024-5957

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.

Fix: 11.1.7.97+
Fix from $1,950 2024-09-05