Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Bludit HIGH 8.2
CVE-2024-24554

Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. …

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Unclassified MEDIUM 5.4
CVE-2024-37897

SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and W…

Patch available
Fix from $1,600 2024-06-20
Lifeline Donation CRITICAL 9.8
CVE-2024-5432

The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.6. This is due to insufficien…

Fix: after 1.2.6
Fix from $2,300 2024-06-20
Unclassified MEDIUM 5.4
CVE-2024-38351

Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise other user accounts. In order…

Mitigation only
Fix from $1,600 2024-06-18
Unclassified MEDIUM 5.9
CVE-2024-37893

Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious …

Mitigation only
Fix from $1,600 2024-06-17
Remote Desktop Manager CRITICAL 9.8
CVE-2024-6057

Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compr…

Fix: 2024.1.32.0+
Fix from $2,300 2024-06-17
I HIGH 7.8
CVE-2024-27275

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user withou…

Mitigation only
Fix from $1,950 2024-06-15
Factorytalk View HIGH 7.5
CVE-2024-37368

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with…

Fix: 14.0+
Fix from $1,950 2024-06-14
Nextcloud Server HIGH 7.5
CVE-2024-37313

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfull…

Fix: 21.0.9.17 / 22.2.10.22+
Fix from $1,950 2024-06-14
Factorytalk View HIGH 7.5
CVE-2024-37367

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system …

Fix: 14.0+
Fix from $1,950 2024-06-14
Unclassified CRITICAL 9.8
CVE-2024-3080EPSS 43%

Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.

Mitigation only
Fix from $2,300 2024-06-14
Cray Parallel Application Launch Service CRITICAL 9.8
CVE-2024-22441

HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

Fix: 1.2.14 / 1.3.3+
Fix from $2,300 2024-06-13
Framemaker Publishing Server CRITICAL 9.8
CVE-2024-30299

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in …

Fix: 2020+
Fix from $2,300 2024-06-13
Commerce HIGH 8.1
CVE-2024-34103

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in…

Fix: after 1.4.0
Fix from $1,950 2024-06-13
Vault HIGH 7.5
CVE-2024-5798

Vault and Vault Enterprise did not properly validate the JSON Web Token (JWT) role-bound audience claim when using the Vault JWT auth method. This ma…

Fix: 1.15.9 / 1.16.3+
Fix from $1,950 2024-06-12
Submarine CRITICAL 9.8
CVE-2024-36264

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submari…

Patch available
Fix from $2,300 2024-06-12
Dynamics 365 Business Central HIGH 7.3
CVE-2024-35248

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2024-06-11
Powersys HIGH 7.8
CVE-2024-36266

A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication …

Fix: 3.11+
Fix from $1,950 2024-06-11
Vdesk MEDIUM 6.5
CVE-2022-45168

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code end…

Fix: after 018
Fix from $1,600 2024-06-10
Unclassified HIGH 7.3
CVE-2024-37408

fprintd through 1.94.3 lacks a security attention mechanism, and thus unexpected actions might be authorized by "auth sufficient pam_fprintd.so" for …

Mitigation only
Fix from $1,950 2024-06-08
Clash CRITICAL 9.8
CVE-2024-5732

A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects unknown code of the componen…

Fix: after 0.20.1
Fix from $2,300 2024-06-07
Argo Cd HIGH 7.5
CVE-2024-37152

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings expo…

Fix: 2.9.17 / 2.10.12+
Fix from $1,950 2024-06-06
Two Factor Authentication MEDIUM 6.5
CVE-2024-5658

The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.

Fix: 3.3.4+
Fix from $1,600 2024-06-06
Exynos 9820 Firmware MEDIUM 5.3
CVE-2023-50804

An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100…

Mitigation only
Fix from $1,600 2024-06-05
Integrate Google Drive CRITICAL 9.8
CVE-2024-35670

Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.

Fix: 1.3.94+
Fix from $2,300 2024-06-04
Booster For Woocommerce MEDIUM 6.5
CVE-2023-51511

Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.T…

Fix: 7.1.3+
Fix from $1,600 2024-06-04
Booster For Woocommerce HIGH 8.8
CVE-2023-48747

Improper Authentication vulnerability in Pluggabl LLC Booster for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This is…

Fix: 7.1.3+
Fix from $1,950 2024-06-04
Defender CRITICAL 9.8
CVE-2023-47189

Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affect…

Fix: 4.2.1+
Fix from $2,300 2024-06-04
Unclassified HIGH 7.5
CVE-2023-46630

Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Properly Constrained by ACLs.This…

Mitigation only
Fix from $1,950 2024-06-04
Unclassified CRITICAL 9.8
CVE-2024-37019

Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.

Mitigation only
Fix from $2,300 2024-06-03