Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Zzcms MEDIUM 5.3
CVE-2024-44821

ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the capt…

Fix: after 2023
Fix from $1,600 2024-09-04
Satellite CRITICAL 9.8
CVE-2024-7012

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…

Mitigation only
Fix from $2,300 2024-09-04
Satellite CRITICAL 9.8
CVE-2024-7923

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…

Mitigation only
Fix from $2,300 2024-09-04
Pixelyoursite HIGH 7.5
CVE-2024-7870

The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable to Sensitive Information Expo…

Fix: 9.7.2 / 10.4.3+
Fix from $1,950 2024-09-04
Ws Ftp Server HIGH 8.1
CVE-2024-7745

In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to …

Fix: 8.8.8+
Fix from $1,950 2024-08-28
Unclassified HIGH 8.8
CVE-2024-45346

The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At …

No fix yet
Fix from $1,950 2024-08-28
Flowise HIGH 8.1
CVE-2024-8181EPSS 45%

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints a…

Mitigation only
Fix from $1,950 2024-08-27
Netskope HIGH 7.5
CVE-2024-7401

Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication pa…

Mitigation only
Fix from $1,950 2024-08-26
Unclassified HIGH 8.1
CVE-2024-36444

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.

Mitigation only
Fix from $1,950 2024-08-22
Ghost MEDIUM 6.5
CVE-2024-43409

Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform me…

Fix: 5.89.5+
Fix from $1,600 2024-08-20
Ivg Webmax CRITICAL 9.8
CVE-2024-42336

Servision - CWE-287: Improper Authentication

Mitigation only
Fix from $2,300 2024-08-20
Spring Security HIGH 7.5
CVE-2024-38810

Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.

Fix: 6.3.2+
Fix from $1,950 2024-08-20
Ultimate Membership Pro CRITICAL 9.8
CVE-2024-43240

Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a …

Fix: after 12.6
Fix from $2,300 2024-08-19
Upkeeper Manager CRITICAL 9.8
CVE-2024-42462

Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager…

Fix: 5.1.10+
Fix from $2,300 2024-08-16
Gncc C2 Firmware MEDIUM 6.8
CVE-2024-31800

Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the U…

No fix yet
Fix from $1,600 2024-08-15
Unclassified HIGH 8.6
CVE-2024-6078

CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies…

Mitigation only
Fix from $1,950 2024-08-14
Big Ip Next Central Manager MEDIUM 5.3
CVE-2024-37028

BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.  Note: Software versions which have reached E…

Fix: 20.2.1+
Fix from $1,600 2024-08-14
Goanywhere Managed File Transfer MEDIUM 6.5
CVE-2024-25157

An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permis…

Fix: 7.6.0+
Fix from $1,600 2024-08-14
Virtual Traffic Manager CRITICAL 9.8
CVE-2024-7593 KEVEPSS 100%

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t…

Patch available
Fix from $2,300 2024-08-13
Traccar CRITICAL 9.8
CVE-2024-7746

Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue a…

Fix: after 6.0
Fix from $2,300 2024-08-13
Unclassified MEDIUM 5.9
CVE-2024-35775

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Authentication vulnerability in Soliloquy Team …

Mitigation only
Fix from $1,600 2024-08-12
GitLab MEDIUM 5.4
CVE-2024-4784

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassi…

Fix: 17.0.6 / 17.1.4+
Fix from $1,600 2024-08-08
Emui HIGH 7.8
CVE-2024-42038

Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confiden…

Mitigation only
Fix from $1,950 2024-08-08
Endpoint Manager Mobile HIGH 7.5
CVE-2024-36132

Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive…

Fix: 12.1.0.1+
Fix from $1,950 2024-08-07
Endpoint Manager Mobile MEDIUM 6.5
CVE-2024-34788

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive in…

Fix: 12.1.0.1+
Fix from $1,600 2024-08-07
Endpoint Manager Mobile CRITICAL 9.8
CVE-2024-36130

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute …

Fix: 12.1.0.1+
Fix from $2,300 2024-08-07
Unclassified CRITICAL 9.3
CVE-2024-7395

An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a passwo…

Mitigation only
Fix from $2,300 2024-08-05
Unclassified HIGH 7.3
CVE-2022-4001

An authentication bypass vulnerability could allow an attacker to access API functions without authentication.

Mitigation only
Fix from $1,950 2024-07-31
Q14 Firmware HIGH 7.2
CVE-2022-4002

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

Fix: 1.5.0.16+
Fix from $1,950 2024-07-31
Pcmanager HIGH 7.8
CVE-2019-6197

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Fix: 2.8.90.11211+
Fix from $1,950 2024-07-31