Vulnerability index

Browse CVEs

4,342 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
315 5g Iot Modem Firmware HIGH 7.5
CVE-2023-43551

Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Secur…

Mitigation only
Fix from $1,950 2024-06-03
Unclassified HIGH 8.8
CVE-2024-5201

Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege of another user via HTTP Req…

No fix yet
Fix from $1,950 2024-05-23
Unclassified MEDIUM 5.3
CVE-2024-28188

Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-schedu…

Patch available
Fix from $1,600 2024-05-23
Veeam Backup \& Replication CRITICAL 9.8
CVE-2024-29849EPSS 17%

Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

Fix: 12.1.2.172+
Fix from $2,300 2024-05-22
Emlog HIGH 8.1
CVE-2024-5044

A vulnerability was found in Emlog Pro 2.3.4. It has been classified as problematic. This affects an unknown part of the component Cookie Handler. Th…

No fix yet
Fix from $1,950 2024-05-17
Simple Membership HIGH 8.8
CVE-2023-41956

Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.

Fix: 4.3.5+
Fix from $1,950 2024-05-17
Unclassified MEDIUM 5.5
CVE-2024-35184

Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prio…

Patch available
Fix from $1,600 2024-05-15
Imanager CRITICAL 9.8
CVE-2024-3487

Broken Authentication vulnerability discovered in OpenText™ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain paramete…

Fix: 3.2.6+
Fix from $2,300 2024-05-15
Unclassified HIGH 8.8
CVE-2024-4129

Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication By…

Mitigation only
Fix from $1,950 2024-05-14
Unclassified CRITICAL 9.8
CVE-2024-3263

YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for syst…

Mitigation only
Fix from $2,300 2024-05-14
Fedora CRITICAL 9.1
CVE-2024-34340

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set t…

Fix: 1.2.27+
Fix from $2,300 2024-05-14
Extremexos HIGH 8.0
CVE-2020-18305

Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing …

Fix: 22.7+
Fix from $1,950 2024-05-14
Unclassified MEDIUM 6.7
CVE-2024-4601

An incorrect authentication vulnerability has been found in Socomec Net Vision affecting version 7.20. This vulnerability allows an attacker to perfo…

Mitigation only
Fix from $1,600 2024-05-07
Archer MEDIUM 5.3
CVE-2024-34093

An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attacker cou…

Fix: 2024.03+
Fix from $1,600 2024-05-06
Dir 845l Firmware CRITICAL 9.1
CVE-2024-33110

D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.

Fix: after 1.01krb03
Fix from $2,300 2024-05-06
Prosafe Network Management System CRITICAL 9.8
CVE-2023-38096EPSS 82%

NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp…

Fix: 1.7.0.20+
Fix from $2,300 2024-05-03
Unclassified HIGH 7.5
CVE-2024-26331EPSS 51%

ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session…

Mitigation only
Fix from $1,950 2024-04-30
Unclassified HIGH 8.8
CVE-2024-4303

ArmorX Android APP's multi-factor authentication (MFA) for the login function is not properly implemented. Remote attackers who obtain user credentia…

Mitigation only
Fix from $1,950 2024-04-29
Media Streaming Add On CRITICAL 9.8
CVE-2023-47222

An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow us…

Fix: 500.1.1.5+
Fix from $2,300 2024-04-26
Vp59 Firmware MEDIUM 6.8
CVE-2024-30939

An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an acc…

No fix yet
Fix from $1,600 2024-04-25
Build Of Keycloak HIGH 8.8
CVE-2023-6787

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijack…

Fix: 22.0.10 / 24.0.3+
Fix from $1,950 2024-04-25
GitLab HIGH 8.8
CVE-2024-4024EPSS 15%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4,…

Fix: 16.9.6 / 16.10.4+
Fix from $1,950 2024-04-25
Unclassified MEDIUM 5.0
CVE-2023-3597

A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows…

Mitigation only
Fix from $1,600 2024-04-25
Unclassified CRITICAL 9.8
CVE-2023-51484

Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as Us…

Mitigation only
Fix from $2,300 2024-04-25
Unclassified CRITICAL 9.9
CVE-2023-51482

Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

Mitigation only
Fix from $2,300 2024-04-25
Build App Online CRITICAL 9.8
CVE-2023-51478

Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a thro…

Fix: 1.0.20+
Fix from $2,300 2024-04-25
Unclassified HIGH 8.2
CVE-2023-51471

Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Accessing Functionality Not Properly Constrained by ACLs.This issue…

Mitigation only
Fix from $1,950 2024-04-24
Unclassified CRITICAL 9.8
CVE-2023-51472

Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affects Checkout Mestres WP: from n…

Mitigation only
Fix from $2,300 2024-04-24
Unclassified CRITICAL 9.8
CVE-2023-51477

Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Constrained by ACLs.This issue af…

Mitigation only
Fix from $2,300 2024-04-24
Bookingpress CRITICAL 9.8
CVE-2023-51405

Improper Authentication vulnerability in Repute Infosystems BookingPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

Fix: 1.0.75+
Fix from $2,300 2024-04-24