Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Pcmanager HIGH 7.8
CVE-2019-6198

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Fix: 2.8.90.11211+
Fix from $1,950 2024-07-31
Safari MEDIUM 5.3
CVE-2024-40794

This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private …

Fix: 14.6 / 17.6+
Fix from $1,600 2024-07-29
Moveit Transfer CRITICAL 9.8
CVE-2024-6576

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: …

Fix: 2023.0.12 / 2023.1.7+
Fix from $2,300 2024-07-29
Unclassified HIGH 8.3
CVE-2024-7050

Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular scenarios.Th…

Mitigation only
Fix from $1,950 2024-07-26
Craft Cms HIGH 7.5
CVE-2024-41800

Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to…

Fix: 5.2.3+
Fix from $1,950 2024-07-25
Teamcity HIGH 7.5
CVE-2024-41829

In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection

Fix: 2024.07+
Fix from $1,950 2024-07-22
Unclassified MEDIUM 5.4
CVE-2024-40648

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto cra…

Patch available
Fix from $1,600 2024-07-18
Access Rights Manager HIGH 8.3
CVE-2024-28992

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23470

The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vuln…

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23471

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an…

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23465

The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthentica…

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Service Interconnect MEDIUM 5.3
CVE-2024-6535

A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift…

Mitigation only
Fix from $1,600 2024-07-17
3par Service Processor Firmware CRITICAL 9.8
CVE-2024-22442

The vulnerability could be remotely exploited to bypass authentication.

Fix: 5.1.2.0+
Fix from $2,300 2024-07-16
Mattermost Mobile MEDIUM 6.5
CVE-2024-39767

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which …

Fix: 2.17.0+
Fix from $1,600 2024-07-15
Unclassified HIGH 8.8
CVE-2024-39340

The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in bo…

Mitigation only
Fix from $1,950 2024-07-12
Npcm750r Firmware MEDIUM 6.7
CVE-2024-38433

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses th…

Fix: 10.10.19+
Fix from $1,600 2024-07-11
Instawp Connect CRITICAL 9.8
CVE-2024-6397

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including…

Fix: 0.1.0.45+
Fix from $2,300 2024-07-11
Netscaler Console HIGH 8.8
CVE-2024-6235EPSS 21%

Sensitive information disclosure in NetScaler Console

Fix: 14.1-25.53+
Fix from $1,950 2024-07-10
Windows Server 2008 MEDIUM 5.9
CVE-2024-38099

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

Fix: 10.0.14393.7159 / 10.0.17763.6054+
Fix from $1,600 2024-07-09
Mattermost MEDIUM 5.9
CVE-2024-39830

Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time co…

Fix: 9.5.6 / 9.6.3+
Fix from $1,600 2024-07-03
Unclassified HIGH 8.6
CVE-2024-3826

In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.

No fix yet
Fix from $1,950 2024-07-02
Smartthings HIGH 7.5
CVE-2024-34596

Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.

Fix: 1.8.17+
Fix from $1,950 2024-07-02
Android HIGH 8.8
CVE-2024-20890

Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.

Mitigation only
Fix from $1,950 2024-07-02
N Central CRITICAL 9.8
CVE-2024-28200

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central p…

Fix: 2024.2+
Fix from $2,300 2024-07-01
Unclassified HIGH 7.5
CVE-2024-38523

Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authentication flow has multiple issu…

Patch available
Fix from $1,950 2024-06-27
Unclassified HIGH 8.8
CVE-2024-23767

An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network c…

Mitigation only
Fix from $1,950 2024-06-26
Whatsup Gold HIGH 8.6
CVE-2024-5012

In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability a…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Moveit Gateway CRITICAL 9.1
CVE-2024-5805EPSS 8%

Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.…

Mitigation only
Fix from $2,300 2024-06-25
Moveit Transfer CRITICAL 9.8
CVE-2024-5806EPSS 81%

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer:…

Fix: 2023.0.11 / 2023.1.6+
Fix from $2,300 2024-06-25
Cloud Foundation HIGH 7.2
CVE-2024-37085 KEVEPSS 26%

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access…

Fix: 5.2+
Fix from $1,950 2024-06-25